From 6b14185dfb67ad3352b25b93e811a1c440c66fe4 Mon Sep 17 00:00:00 2001 From: mvelazco Date: Thu, 9 Dec 2021 13:51:31 -0500 Subject: [PATCH] updating docs --- docs/_data/navigation.yml | 2 - docs/_pages/adversary_tactics.md | 4 +- docs/_pages/detections.md | 62 ++------ docs/_pages/stories.md | 4 +- .../ransomware_investigate_and_contain.md | 30 ---- ...0-first_time_seen_child_process_of_zoom.md | 4 +- ...20-07-07-remote_desktop_network_traffic.md | 2 +- ...emote_desktop_process_running_on_system.md | 2 +- ...computer_changed_with_anonymous_account.md | 4 +- ...tivity_related_to_pass_the_hash_attacks.md | 2 +- ...e_of_fgdump_and_cachedump_with_s_option.md | 97 ------------ ...e_of_fgdump_and_cachedump_with_v_option.md | 96 ------------ ...icative_of_lazagne_command_line_options.md | 97 ------------ ...icrosoft_debuggers_peek_into_the_kernel.md | 99 ------------ ...oft_debuggers_via_z_command_line_option.md | 95 ------------ ..._present_in_powersploit_and_dsinternals.md | 95 ------------ ...internals_credential_conversion_modules.md | 100 ------------ ...ndicative_of_use_of_dsinternals_modules.md | 100 ------------ ...n_indicative_of_use_of_mimikatz_modules.md | 97 ------------ ...ndicative_of_use_of_powersploit_modules.md | 97 ------------ ...stolen_credentials_via_mimikatz_modules.md | 146 ------------------ ...len_credentials_via_powersploit_modules.md | 144 ----------------- ...ential_strength_via_dsinternals_modules.md | 118 -------------- ...tores_and_services_via_mimikatz_modules.md | 126 --------------- ...ing_credentials_via_dsinternals_modules.md | 110 ------------- ...etting_credentials_via_mimikatz_modules.md | 107 ------------- ...ing_credentials_via_powersploit_modules.md | 107 ------------- ...len_credentials_via_powersploit_modules.md | 102 ------------ ...ccounts_and_groups_via_mimikatz_modules.md | 107 ------------- ...ps_and_policies_via_powersploit_modules.md | 107 ------------- ...e_opportunities_via_powersploit_modules.md | 124 --------------- ...defensive_tools_via_powersploit_modules.md | 107 ------------- ...n_opportunities_via_powersploit_modules.md | 106 ------------- ...king_opportunities_via_mimikatz_modules.md | 108 ------------- ..._infrastructure_via_powersploit_modules.md | 111 ------------- ...ers_and_domains_via_powersploit_modules.md | 103 ------------ ...ccess_to_computers_via_mimikatz_modules.md | 95 ------------ ...system_elements_via_powersploit_modules.md | 127 --------------- ...esses_and_services_via_mimikatz_modules.md | 103 ------------ ...o_shared_resources_via_mimikatz_modules.md | 107 ------------- ...hared_resources_via_powersploit_modules.md | 107 ------------- ...of_connectivity_via_powersploit_modules.md | 107 ------------- ...to_user_content_via_powersploit_modules.md | 108 ------------- ...ccount_creation_via_powersploit_modules.md | 96 ------------ ...l_deletion_of_logs_via_mimikatz_modules.md | 96 ------------ ...ing_of_accounts_via_dsinternals_modules.md | 103 ------------ ...ts_and_policies_via_dsinternals_modules.md | 105 ------------- ...ectory_elements_via_powersploit_modules.md | 106 ------------- ...and_persistence_via_powersploit_modules.md | 109 ------------- ...rivilege_elevation_via_mimikatz_modules.md | 102 ------------ ...nd_process_control_via_mimikatz_modules.md | 105 ------------- ...process_control_via_powersploit_modules.md | 107 ------------- ...rohibited_applications_spawning_cmd_exe.md | 7 +- ...heduled_task_created_within_public_path.md | 2 +- .../2021-09-14-net_localgroup_discovery.md | 1 + ...9-16-detect_psexec_with_accepteula_flag.md | 2 +- .../2021-09-16-detect_renamed_psexec.md | 2 +- ..._observed_by_an_event_collecting_device.md | 10 +- ...ows_service_creation_on_remote_endpoint.md | 2 +- ...s_service_initiation_on_remote_endpoint.md | 2 +- ...ocess_instantiation_via_winrm_and_winrs.md | 2 +- ...sk_creation_on_remote_endpoint_using_at.md | 2 +- ...uled_task_initiation_on_remote_endpoint.md | 2 +- ...chtasks_scheduling_job_on_remote_system.md | 2 +- ...12-remote_process_instantiation_via_wmi.md | 2 +- ...s_instantiation_via_dcom_and_powershell.md | 2 +- ...on_via_dcom_and_powershell_script_block.md | 2 +- ...ss_instantiation_via_wmi_and_powershell.md | 2 +- ...ion_via_wmi_and_powershell_script_block.md | 2 +- ...021-11-15-sdelete_application_execution.md | 3 +- ..._instantiation_via_winrm_and_powershell.md | 2 +- ...n_via_winrm_and_powershell_script_block.md | 2 +- ...ile_written_in_administrative_smb_share.md | 4 +- ...sion_on_remote_endpoint_with_powershell.md | 2 +- ...lateral_movement_commandline_parameters.md | 2 +- ...services_lolbas_execution_process_spawn.md | 4 +- ...-svchost_lolbas_execution_process_spawn.md | 4 +- ...ce_created_with_suspicious_service_path.md | 2 +- ...dows_service_created_within_public_path.md | 2 +- ...wmiprsve_lolbas_execution_process_spawn.md | 4 +- ...provhost_lolbas_execution_process_spawn.md | 2 +- ...1-23-mmc_lolbas_execution_process_spawn.md | 2 +- ... 2021-11-24-attempt_to_delete_services.md} | 19 ++- ...2021-11-24-attempt_to_disable_services.md} | 6 +- ...dential_dump_from_registry_via_reg_exe.md} | 20 ++- ...29-deny_permission_using_cacls_utility.md} | 11 +- ...detect_dump_lsass_memory_using_comsvcs.md} | 17 +- ...sible_lateral_movement_powershell_spawn.md | 137 ++++++++++++++++ ...-randomly_generated_scheduled_task_name.md | 110 +++++++++++++ ...randomly_generated_windows_service_name.md | 106 +++++++++++++ docs/_posts/2021-11-30-delete_a_net_user.md | 4 +- ...=> 2021-11-30-disable_net_user_account.md} | 13 +- ...-first_time_seen_command_line_argument.md} | 20 ++- ...0-grant_permission_using_cacls_utility.md} | 11 +- ...fy_acls_permission_of_files_or_folders.md} | 11 +- ...ash_observed_at_the_destination_device.md} | 15 +- ...rare_parent-child_process_relationship.md} | 15 +- ...2021-11-30-resize_shadowstorage_volume.md} | 8 +- ...r_of_computer_service_tickets_requested.md | 107 +++++++++++++ ...f_remote_endpoint_authentication_events.md | 106 +++++++++++++ ...-12-03-detect_rclone_command-line_usage.md | 104 +++++++++++++ .../2021-12-03-short_lived_scheduled_task.md | 102 ++++++++++++ ...ndows_curl_upload_to_remote_destination.md | 108 +++++++++++++ ...7-bcdedit_failure_recovery_modification.md | 99 ++++++++++++ ...-07-dns_exfiltration_using_nslookup_app.md | 105 +++++++++++++ docs/_posts/2021-12-07-fsutil_zeroing_file.md | 98 ++++++++++++ ...021-12-07-wbadmin_delete_system_backups.md | 101 ++++++++++++ .../active_directory_lateral_movement.md | 84 ++++++++++ docs/_stories/command_and_control.md | 4 +- docs/_stories/credential_dumping.md | 15 +- docs/_stories/darkside_ransomware.md | 4 +- docs/_stories/data_exfiltration.md | 4 +- docs/_stories/dynamic_dns.md | 4 +- docs/_stories/ingress_tool_transfer.md | 4 +- docs/_stories/malicious_powershell.md | 11 +- docs/_stories/ransomware.md | 8 +- docs/_stories/ryuk_ransomware.md | 5 +- docs/_stories/suspicious_dns_traffic.md | 4 +- docs/_stories/unusual_processes.md | 7 +- docs/_stories/windows_discovery_techniques.md | 20 +-- docs/_stories/windows_log_manipulation.md | 1 - .../windows_persistence_techniques.md | 11 +- docs/_stories/windows_privilege_escalation.md | 5 +- docs/_stories/windows_service_abuse.md | 5 +- docs/_stories/xmrig.md | 4 +- docs/index.markdown | 4 +- 126 files changed, 1579 insertions(+), 4764 deletions(-) delete mode 100644 docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md delete mode 100644 docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md delete mode 100644 docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md delete mode 100644 docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md delete mode 100644 docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md delete mode 100644 docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md delete mode 100644 docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md delete mode 100644 docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md delete mode 100644 docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md delete mode 100644 docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md delete mode 100644 docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md delete mode 100644 docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md delete mode 100644 docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md rename docs/_posts/{2021-11-30-attempt_to_delete_services.md => 2021-11-24-attempt_to_delete_services.md} (84%) rename docs/_posts/{2021-11-30-attempt_to_disable_services.md => 2021-11-24-attempt_to_disable_services.md} (96%) rename docs/_posts/{2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md => 2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md} (72%) rename docs/_posts/{2021-06-14-deny_permission_using_cacls_utility.md => 2021-11-29-deny_permission_using_cacls_utility.md} (89%) rename docs/_posts/{2020-09-15-detect_dump_lsass_memory_using_comsvcs.md => 2021-11-29-detect_dump_lsass_memory_using_comsvcs.md} (70%) create mode 100644 docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md create mode 100644 docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md create mode 100644 docs/_posts/2021-11-29-randomly_generated_windows_service_name.md rename docs/_posts/{2021-12-01-disable_net_user_account.md => 2021-11-30-disable_net_user_account.md} (92%) rename docs/_posts/{2021-2-1-first_time_seen_command_line_argument.md => 2021-11-30-first_time_seen_command_line_argument.md} (76%) rename docs/_posts/{2021-06-14-grant_permission_using_cacls_utility.md => 2021-11-30-grant_permission_using_cacls_utility.md} (88%) rename docs/_posts/{2021-06-15-modify_acls_permission_of_files_or_folders.md => 2021-11-30-modify_acls_permission_of_files_or_folders.md} (93%) rename docs/_posts/{2021-11-05-potential_pass_the_token_or_hash_observed_at_the_destination_device.md => 2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md} (85%) rename docs/_posts/{2021-05-20-rare_parent-child_process_relationship.md => 2021-11-30-rare_parent-child_process_relationship.md} (89%) rename docs/_posts/{2021-06-21-resize_shadowstorage_volume.md => 2021-11-30-resize_shadowstorage_volume.md} (89%) create mode 100644 docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md create mode 100644 docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md create mode 100644 docs/_posts/2021-12-03-detect_rclone_command-line_usage.md create mode 100644 docs/_posts/2021-12-03-short_lived_scheduled_task.md create mode 100644 docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md create mode 100644 docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md create mode 100644 docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md create mode 100644 docs/_posts/2021-12-07-fsutil_zeroing_file.md create mode 100644 docs/_posts/2021-12-07-wbadmin_delete_system_backups.md create mode 100644 docs/_stories/active_directory_lateral_movement.md diff --git a/docs/_data/navigation.yml b/docs/_data/navigation.yml index cd73da3ebf..c837d67511 100644 --- a/docs/_data/navigation.yml +++ b/docs/_data/navigation.yml @@ -38,8 +38,6 @@ detections: url: /detections/privilege_escalation/ - title: Reconnaissance url: /detections/reconnaissance/ - - title: Resource Development - url: /detections/resource_development/ - title: "Datamodel" children: - title: Authentication diff --git a/docs/_pages/adversary_tactics.md b/docs/_pages/adversary_tactics.md index 31fdf3eb01..147a06b8ac 100644 --- a/docs/_pages/adversary_tactics.md +++ b/docs/_pages/adversary_tactics.md @@ -11,6 +11,7 @@ sidebar: | Name | Technique | Tactic | | ----------- | ----------- |--------------| | [Active Directory Discovery](/stories/active_directory_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | +| [Active Directory Lateral Movement](/stories/active_directory_lateral_movement/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [Lateral Movement](/tags/#lateral-movement) | | [Active Directory Password Spraying](/stories/active_directory_password_spraying/) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Credential Access](/tags/#credential-access) | | [BITS Jobs](/stories/bits_jobs/) | [BITS Jobs](/tags/#bits-jobs) | [Defense Evasion](/tags/#defense-evasion) | | [Baron Samedit CVE-2021-3156](/stories/baron_samedit_cve-2021-3156/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | [Privilege Escalation](/tags/#privilege-escalation) | @@ -27,7 +28,6 @@ sidebar: | [F5 TMUI RCE CVE-2020-5902](/stories/f5_tmui_rce_cve-2020-5902/) | [Exploit Public-Facing Application](/tags/#exploit-public-facing-application) | [Initial Access](/tags/#initial-access) | | [HAFNIUM Group](/stories/hafnium_group/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | [Persistence](/tags/#persistence) | | [Ingress Tool Transfer](/stories/ingress_tool_transfer/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | [Command And Control](/tags/#command-and-control) | -| [Lateral Movement](/stories/lateral_movement/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [Lateral Movement](/tags/#lateral-movement) | | [Malicious PowerShell](/stories/malicious_powershell/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | [Reconnaissance](/tags/#reconnaissance) | | [Masquerading - Rename System Utilities](/stories/masquerading_-_rename_system_utilities/) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | | [Meterpreter](/stories/meterpreter/) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Discovery](/tags/#discovery) | @@ -56,7 +56,7 @@ sidebar: | [Trusted Developer Utilities Proxy Execution MSBuild](/stories/trusted_developer_utilities_proxy_execution_msbuild/) | [Masquerading](/tags/#masquerading), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Rename System Utilities](/tags/#rename-system-utilities), [MSBuild](/tags/#msbuild) | [Defense Evasion](/tags/#defense-evasion) | | [Windows DNS SIGRed CVE-2020-1350](/stories/windows_dns_sigred_cve-2020-1350/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [Execution](/tags/#execution) | | [Windows Defense Evasion Tactics](/stories/windows_defense_evasion_tactics/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | -| [Windows Discovery Techniques](/stories/windows_discovery_techniques/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [Persistence](/tags/#persistence) | +| [Windows Discovery Techniques](/stories/windows_discovery_techniques/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | | [Windows Log Manipulation](/stories/windows_log_manipulation/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | | [Windows Persistence Techniques](/stories/windows_persistence_techniques/) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | | [Windows Privilege Escalation](/stories/windows_privilege_escalation/) | [Time Providers](/tags/#time-providers), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | [Persistence](/tags/#persistence) | \ No newline at end of file diff --git a/docs/_pages/detections.md b/docs/_pages/detections.md index 0eee0b17f5..40fe7f976b 100644 --- a/docs/_pages/detections.md +++ b/docs/_pages/detections.md @@ -55,18 +55,16 @@ sidebar: | [Anomalous usage of Archive Tools](/endpoint/anomalous_usage_of_archive_tools/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Anomaly | | [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | -| [Applying Stolen Credentials via Mimikatz modules](/endpoint/applying_stolen_credentials_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Modify Authentication Process](/tags/#modify-authentication-process), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | -| [Applying Stolen Credentials via PowerSploit modules](/endpoint/applying_stolen_credentials_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | -| [Assessment of Credential Strength via DSInternals modules](/endpoint/assessment_of_credential_strength_via_dsinternals_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Account Discovery](/tags/#account-discovery), [Password Policy Discovery](/tags/#password-policy-discovery), [Unsecured Credentials](/tags/#unsecured-credentials), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | | [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | TTP | | [Attempt To Add Certificate To Untrusted Store](/endpoint/attempt_to_add_certificate_to_untrusted_store/) | [Install Root Certificate](/tags/#install-root-certificate), [Subvert Trust Controls](/tags/#subvert-trust-controls) | TTP | -| [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop) | TTP | +| [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Attempt To Stop Security Service](/endpoint/attempt_to_stop_security_service/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager) | TTP | | [Auto Admin Logon Registry Entry](/endpoint/auto_admin_logon_registry_entry/) | [Credentials in Registry](/tags/#credentials-in-registry), [Unsecured Credentials](/tags/#unsecured-credentials) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | +| [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [BITS Job Persistence](/endpoint/bits_job_persistence/) | [BITS Jobs](/tags/#bits-jobs) | TTP | | [BITSAdmin Download File](/endpoint/bitsadmin_download_file/) | [BITS Jobs](/tags/#bits-jobs), [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Batch File Write to System32](/endpoint/batch_file_write_to_system32/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | TTP | @@ -116,18 +114,9 @@ sidebar: | [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of FGDump and CacheDump with s option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of FGDump and CacheDump with v option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of Lazagne command line options](/endpoint/credential_extraction_indicative_of_lazagne_command_line_options/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | -| [Credential Extraction indicative of use of DSInternals credential conversion modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of DSInternals modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of Mimikatz modules](/endpoint/credential_extraction_indicative_of_use_of_mimikatz_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of PowerSploit modules](/endpoint/credential_extraction_indicative_of_use_of_powersploit_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction native Microsoft debuggers peek into the kernel](/endpoint/credential_extraction_native_microsoft_debuggers_peek_into_the_kernel/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction native Microsoft debuggers via z command line option](/endpoint/credential_extraction_native_microsoft_debuggers_via_z_command_line_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](/endpoint/credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [DLLHost with no Command Line Arguments with Network](/endpoint/dllhost_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | TTP | | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | | [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [DSQuery Domain Discovery](/endpoint/dsquery_domain_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | @@ -180,6 +169,7 @@ sidebar: | [Detect Prohibited Applications Spawning cmd exe](/endpoint/detect_prohibited_applications_spawning_cmd_exe/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Anomaly | | [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | | [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | +| [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | | [Detect Rare Executables]() | None | Anomaly | | [Detect Regasm Spawning a Process](/endpoint/detect_regasm_spawning_a_process/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | | [Detect Regasm with Network Connection](/endpoint/detect_regasm_with_network_connection/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Regsvcs/Regasm](/tags/#regsvcs/regasm) | TTP | @@ -231,7 +221,7 @@ sidebar: | [Disable Defender Submit Samples Consent Feature](/endpoint/disable_defender_submit_samples_consent_feature/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop) | TTP | +| [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop), [Valid Accounts](/tags/#valid-accounts) | TTP | | [Disable Registry Tool](/endpoint/disable_registry_tool/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Schedule Task](/endpoint/disable_schedule_task/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Security Logs Using MiniNt Registry](/endpoint/disable_security_logs_using_minint_registry/) | [Modify Registry](/tags/#modify-registry) | TTP | @@ -299,9 +289,10 @@ sidebar: | [Firewall Allowed Program Enable](/endpoint/firewall_allowed_program_enable/) | [Disable or Modify System Firewall](/tags/#disable-or-modify-system-firewall), [Impair Defenses](/tags/#impair-defenses) | Anomaly | | [First Time Seen Child Process of Zoom](/endpoint/first_time_seen_child_process_of_zoom/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | Anomaly | | [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | -| [First time seen command line argument](/endpoint/first_time_seen_command_line_argument/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Regsvr32](/tags/#regsvr32), [Indirect Command Execution](/tags/#indirect-command-execution) | Anomaly | +| [First time seen command line argument](/endpoint/first_time_seen_command_line_argument/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Indirect Command Execution](/tags/#indirect-command-execution) | Anomaly | | [FodHelper UAC Bypass](/endpoint/fodhelper_uac_bypass/) | [Modify Registry](/tags/#modify-registry), [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [GCP Detect gcploit framework](/cloud/gcp_detect_gcploit_framework/) | [Valid Accounts](/tags/#valid-accounts) | TTP | | [GCP Kubernetes cluster pod scan detection](/cloud/gcp_kubernetes_cluster_pod_scan_detection/) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | Hunting | | [GPUpdate with no Command Line Arguments with Network](/endpoint/gpupdate_with_no_command_line_arguments_with_network/) | [Process Injection](/tags/#process-injection) | TTP | @@ -368,16 +359,6 @@ sidebar: | [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Icacls Deny Command](/endpoint/icacls_deny_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [IcedID Exfiltrated Archived File Creation](/endpoint/icedid_exfiltrated_archived_file_creation/) | [Archive via Utility](/tags/#archive-via-utility), [Archive Collected Data](/tags/#archive-collected-data) | Hunting | -| [Illegal Access To User Content via PowerSploit modules](/endpoint/illegal_access_to_user_content_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Screen Capture](/tags/#screen-capture), [Audio Capture](/tags/#audio-capture), [Remote Service Session Hijacking](/tags/#remote-service-session-hijacking) | TTP | -| [Illegal Account Creation via PowerSploit modules](/endpoint/illegal_account_creation_via_powersploit_modules/) | [Establish Accounts](/tags/#establish-accounts) | TTP | -| [Illegal Deletion of Logs via Mimikatz modules](/endpoint/illegal_deletion_of_logs_via_mimikatz_modules/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | -| [Illegal Enabling or Disabling of Accounts via DSInternals modules](/endpoint/illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Illegal Management of Active Directory Elements and Policies via DSInternals modules](/endpoint/illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules/) | [Account Manipulation](/tags/#account-manipulation), [Rogue Domain Controller](/tags/#rogue-domain-controller), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Illegal Management of Computers and Active Directory Elements via PowerSploit modules](/endpoint/illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules/) | [Account Manipulation](/tags/#account-manipulation), [Rogue Domain Controller](/tags/#rogue-domain-controller), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Illegal Privilege Elevation and Persistence via PowerSploit modules](/endpoint/illegal_privilege_elevation_and_persistence_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Illegal Privilege Elevation via Mimikatz modules](/endpoint/illegal_privilege_elevation_via_mimikatz_modules/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Illegal Service and Process Control via Mimikatz modules](/endpoint/illegal_service_and_process_control_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | -| [Illegal Service and Process Control via PowerSploit modules](/endpoint/illegal_service_and_process_control_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | | [Impacket Lateral Movement Commandline Parameters](/endpoint/impacket_lateral_movement_commandline_parameters/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service) | TTP | | [Interactive Session on Remote Endpoint with PowerShell](/endpoint/interactive_session_on_remote_endpoint_with_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | | [Jscript Execution Using Cscript App](/endpoint/jscript_execution_using_cscript_app/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [JavaScript](/tags/#javascript) | TTP | @@ -473,6 +454,7 @@ sidebar: | [Phishing Email Detection by Machine Learning Method - SSA](/application/phishing_email_detection_by_machine_learning_method_-_ssa/) | [Phishing](/tags/#phishing) | Anomaly | | [Plain HTTP POST Exfiltrated Data](/network/plain_http_post_exfiltrated_data/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [Possible Browser Pass View Parameter](/endpoint/possible_browser_pass_view_parameter/) | [Credentials from Web Browsers](/tags/#credentials-from-web-browsers), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | Hunting | +| [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell) | TTP | | [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | | [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | | [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | Hunting | @@ -495,7 +477,6 @@ sidebar: | [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Print Spooler Adding A Printer Driver](/endpoint/print_spooler_adding_a_printer_driver/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Print Spooler Failed to Load a Plug-in](/endpoint/print_spooler_failed_to_load_a_plug-in/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | -| [Probing Access with Stolen Credentials via PowerSploit modules](/endpoint/probing_access_with_stolen_credentials_via_powersploit_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Process Creating LNK file in Suspicious Location](/endpoint/process_creating_lnk_file_in_suspicious_location/) | [Phishing](/tags/#phishing), [Spearphishing Link](/tags/#spearphishing-link) | TTP | | [Process Deleting Its Process File Path](/endpoint/process_deleting_its_process_file_path/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Process Execution via WMI](/endpoint/process_execution_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | @@ -506,25 +487,12 @@ sidebar: | [Prohibited Network Traffic Allowed](/network/prohibited_network_traffic_allowed/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [Protocol or Port Mismatch](/network/protocol_or_port_mismatch/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [Protocols passing authentication in cleartext]() | None | TTP | +| [Randomly Generated Scheduled Task Name](/endpoint/randomly_generated_scheduled_task_name/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | Hunting | +| [Randomly Generated Windows Service Name](/endpoint/randomly_generated_windows_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | Hunting | | [Ransomware Notes bulk creation](/endpoint/ransomware_notes_bulk_creation/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Anomaly | | [Rare Parent-Child Process Relationship](/endpoint/rare_parent-child_process_relationship/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task/Job](/tags/#scheduled-task/job), [Software Deployment Tools](/tags/#software-deployment-tools) | Anomaly | | [Recon AVProduct Through Pwh or WMI](/endpoint/recon_avproduct_through_pwh_or_wmi/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | | [Recon Using WMI Class](/endpoint/recon_using_wmi_class/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | -| [Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules](/endpoint/reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Discovery](/tags/#account-discovery), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Reconnaissance and Access to Accounts and Groups via Mimikatz modules](/endpoint/reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Discovery](/tags/#account-discovery), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules](/endpoint/reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules/) | [Trusted Relationship](/tags/#trusted-relationship), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Gather Victim Org Information](/tags/#gather-victim-org-information), [Active Scanning](/tags/#active-scanning) | TTP | -| [Reconnaissance and Access to Computers and Domains via PowerSploit modules](/endpoint/reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Account Discovery](/tags/#account-discovery) | TTP | -| [Reconnaissance and Access to Computers via Mimikatz modules](/endpoint/reconnaissance_and_access_to_computers_via_mimikatz_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | -| [Reconnaissance and Access to Operating System Elements via PowerSploit modules](/endpoint/reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules/) | [Process Discovery](/tags/#process-discovery), [File and Directory Discovery](/tags/#file-and-directory-discovery), [Software](/tags/#software), [Network Service Scanning](/tags/#network-service-scanning), [Query Registry](/tags/#query-registry), [System Service Discovery](/tags/#system-service-discovery), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Software Discovery](/tags/#software-discovery) | TTP | -| [Reconnaissance and Access to Processes and Services via Mimikatz modules](/endpoint/reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules/) | [System Service Discovery](/tags/#system-service-discovery), [Network Service Scanning](/tags/#network-service-scanning), [Process Discovery](/tags/#process-discovery) | TTP | -| [Reconnaissance and Access to Shared Resources via Mimikatz modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_mimikatz_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Reconnaissance and Access to Shared Resources via PowerSploit modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Reconnaissance of Access and Persistence Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | -| [Reconnaissance of Connectivity via PowerSploit modules](/endpoint/reconnaissance_of_connectivity_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Reconnaissance of Credential Stores and Services via Mimikatz modules](/endpoint/reconnaissance_of_credential_stores_and_services_via_mimikatz_modules/) | [Account Manipulation](/tags/#account-manipulation), [Domain Properties](/tags/#domain-properties), [Valid Accounts](/tags/#valid-accounts), [Credentials](/tags/#credentials), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Gather Victim Identity Information](/tags/#gather-victim-identity-information), [Network Trust Dependencies](/tags/#network-trust-dependencies) | TTP | -| [Reconnaissance of Defensive Tools via PowerSploit modules](/endpoint/reconnaissance_of_defensive_tools_via_powersploit_modules/) | [Software](/tags/#software), [Vulnerability Scanning](/tags/#vulnerability-scanning), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Active Scanning](/tags/#active-scanning) | TTP | -| [Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules](/endpoint/reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | | [Recursive Delete of Directory In Batch CMD](/endpoint/recursive_delete_of_directory_in_batch_cmd/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | | [Registry Keys Used For Persistence](/endpoint/registry_keys_used_for_persistence/) | [Registry Run Keys / Startup Folder](/tags/#registry-run-keys-/-startup-folder), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | @@ -595,11 +563,9 @@ sidebar: | [Services Escalate Exe](/endpoint/services_escalate_exe/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Services LOLBAS Execution Process Spawn](/endpoint/services_lolbas_execution_process_spawn/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | | [Set Default PowerShell Execution Policy To Unrestricted or Bypass](/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | -| [Setting Credentials via DSInternals modules](/endpoint/setting_credentials_via_dsinternals_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Setting Credentials via Mimikatz modules](/endpoint/setting_credentials_via_mimikatz_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Setting Credentials via PowerSploit modules](/endpoint/setting_credentials_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | +| [Short Lived Scheduled Task](/endpoint/short_lived_scheduled_task/) | [Scheduled Task](/tags/#scheduled-task) | TTP | | [Short Lived Windows Accounts](/endpoint/short_lived_windows_accounts/) | [Local Account](/tags/#local-account), [Create Account](/tags/#create-account) | TTP | | [SilentCleanup UAC Bypass](/endpoint/silentcleanup_uac_bypass/) | [Bypass User Account Control](/tags/#bypass-user-account-control), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Single Letter Process On Endpoint](/endpoint/single_letter_process_on_endpoint/) | [User Execution](/tags/#user-execution), [Malicious File](/tags/#malicious-file) | TTP | @@ -664,6 +630,8 @@ sidebar: | [Uninstall App Using MsiExec](/endpoint/uninstall_app_using_msiexec/) | [Msiexec](/tags/#msiexec), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution) | TTP | | [Unload Sysmon Filter Driver](/endpoint/unload_sysmon_filter_driver/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Unloading AMSI via Reflection](/endpoint/unloading_amsi_via_reflection/) | [Impair Defenses](/tags/#impair-defenses) | TTP | +| [Unusual Number of Computer Service Tickets Requested](/endpoint/unusual_number_of_computer_service_tickets_requested/) | [Valid Accounts](/tags/#valid-accounts) | Hunting | +| [Unusual Number of Remote Endpoint Authentication Events](/endpoint/unusual_number_of_remote_endpoint_authentication_events/) | [Valid Accounts](/tags/#valid-accounts) | Hunting | | [Unusually Long Command Line]() | None | Anomaly | | [Unusually Long Command Line]() | None | Anomaly | | [Unusually Long Command Line - MLTK]() | None | Anomaly | @@ -674,6 +642,7 @@ sidebar: | [Verclsid CLSID Execution](/endpoint/verclsid_clsid_execution/) | [Verclsid](/tags/#verclsid), [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution) | Hunting | | [W3WP Spawning Shell](/endpoint/w3wp_spawning_shell/) | [Server Software Component](/tags/#server-software-component), [Web Shell](/tags/#web-shell) | TTP | | [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | +| [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [WMI Permanent Event Subscription](/endpoint/wmi_permanent_event_subscription/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | | [WMI Permanent Event Subscription - Sysmon](/endpoint/wmi_permanent_event_subscription_-_sysmon/) | [Windows Management Instrumentation Event Subscription](/tags/#windows-management-instrumentation-event-subscription), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [WMI Recon Running Process Or Services](/endpoint/wmi_recon_running_process_or_services/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | @@ -694,6 +663,7 @@ sidebar: | [Windows AdFind Exe](/endpoint/windows_adfind_exe/) | [Remote System Discovery](/tags/#remote-system-discovery) | TTP | | [Windows Curl Download to Suspicious Path](/endpoint/windows_curl_download_to_suspicious_path/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Windows Curl Upload to Remote Destination](/endpoint/windows_curl_upload_to_remote_destination/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | +| [Windows Curl Upload to Remote Destination](/endpoint/windows_curl_upload_to_remote_destination/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Windows Defender Exclusion Registry Entry](/endpoint/windows_defender_exclusion_registry_entry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Windows DiskCryptor Usage](/endpoint/windows_diskcryptor_usage/) | [Data Encrypted for Impact](/tags/#data-encrypted-for-impact) | Hunting | diff --git a/docs/_pages/stories.md b/docs/_pages/stories.md index 5b3028ad5d..188c2c8c09 100644 --- a/docs/_pages/stories.md +++ b/docs/_pages/stories.md @@ -16,6 +16,7 @@ sidebar: | [AWS Security Hub Alerts]() | None | None | | [AWS User Monitoring](aws_user_monitoring) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | | [Active Directory Discovery](active_directory_discovery) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | +| [Active Directory Lateral Movement](active_directory_lateral_movement) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [Lateral Movement](/tags/#lateral-movement) | | [Active Directory Password Spraying](active_directory_password_spraying) | [Password Spraying](/tags/#password-spraying), [Brute Force](/tags/#brute-force) | [Credential Access](/tags/#credential-access) | | [Apache Struts Vulnerability](apache_struts_vulnerability) | [System Information Discovery](/tags/#system-information-discovery) | [Discovery](/tags/#discovery) | | [Asset Tracking]() | None | None | @@ -56,7 +57,6 @@ sidebar: | [JBoss Vulnerability](jboss_vulnerability) | [System Information Discovery](/tags/#system-information-discovery) | [Discovery](/tags/#discovery) | | [Kubernetes Scanning Activity](kubernetes_scanning_activity) | [Cloud Service Discovery](/tags/#cloud-service-discovery) | [Discovery](/tags/#discovery) | | [Kubernetes Sensitive Object Access Activity]() | None | None | -| [Lateral Movement](lateral_movement) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | [Lateral Movement](/tags/#lateral-movement) | | [Malicious PowerShell](malicious_powershell) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | [Reconnaissance](/tags/#reconnaissance) | | [Masquerading - Rename System Utilities](masquerading_-_rename_system_utilities) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | | [Meterpreter](meterpreter) | [System Owner/User Discovery](/tags/#system-owner/user-discovery) | [Discovery](/tags/#discovery) | @@ -109,7 +109,7 @@ sidebar: | [Use of Cleartext Protocols]() | None | None | | [Windows DNS SIGRed CVE-2020-1350](windows_dns_sigred_cve-2020-1350) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution) | [Execution](/tags/#execution) | | [Windows Defense Evasion Tactics](windows_defense_evasion_tactics) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | [Defense Evasion](/tags/#defense-evasion) | -| [Windows Discovery Techniques](windows_discovery_techniques) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | [Persistence](/tags/#persistence) | +| [Windows Discovery Techniques](windows_discovery_techniques) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | [Discovery](/tags/#discovery) | | [Windows File Extension and Association Abuse](windows_file_extension_and_association_abuse) | [Masquerading](/tags/#masquerading), [Rename System Utilities](/tags/#rename-system-utilities) | [Defense Evasion](/tags/#defense-evasion) | | [Windows Log Manipulation](windows_log_manipulation) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | [Defense Evasion](/tags/#defense-evasion) | | [Windows Persistence Techniques](windows_persistence_techniques) | [Scheduled Task](/tags/#scheduled-task) | [Execution](/tags/#execution) | diff --git a/docs/_playbooks/ransomware_investigate_and_contain.md b/docs/_playbooks/ransomware_investigate_and_contain.md index 224cbff83b..43b255d207 100644 --- a/docs/_playbooks/ransomware_investigate_and_contain.md +++ b/docs/_playbooks/ransomware_investigate_and_contain.md @@ -115,8 +115,6 @@ This playbook investigates and contains ransomware detected on endpoints. - - @@ -696,34 +694,6 @@ This playbook investigates and contains ransomware detected on endpoints. - - - - - - - - - - - - - - - - - - - - - - - - - - - - diff --git a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md index eaceb24d99..e9f3b6a2de 100644 --- a/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md +++ b/docs/_posts/2020-05-20-first_time_seen_child_process_of_zoom.md @@ -15,6 +15,8 @@ tags: - Endpoint --- +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate or build datasets for it, use at your own risk! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -96,4 +98,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/first_time_seen_child_process_of_zoom.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/first_time_seen_child_process_of_zoom.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md index 5233c1b80b..c47e24c064 100644 --- a/docs/_posts/2020-07-07-remote_desktop_network_traffic.md +++ b/docs/_posts/2020-07-07-remote_desktop_network_traffic.md @@ -58,7 +58,7 @@ This search looks for network traffic on TCP/3389, the default port used by remo * [SamSam Ransomware](/stories/samsam_ransomware) * [Ryuk Ransomware](/stories/ryuk_ransomware) * [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md index 0d530566df..6d7527892e 100644 --- a/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md +++ b/docs/_posts/2020-07-21-remote_desktop_process_running_on_system.md @@ -56,7 +56,7 @@ This search looks for the remote desktop process mstsc.exe running on systems up #### Associated Analytic Story * [Hidden Cobra Malware](/stories/hidden_cobra_malware) -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md index afc08467fb..17ff1b5612 100644 --- a/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md +++ b/docs/_posts/2020-09-18-detect_computer_changed_with_anonymous_account.md @@ -15,6 +15,8 @@ tags: - CVE-2020-1472 --- +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate or build datasets for it, use at your own risk! [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -98,4 +100,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_computer_changed_with_anonymous_account.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/detect_computer_changed_with_anonymous_account.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md index 1fb623a3fa..33c3ee77ae 100644 --- a/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md +++ b/docs/_posts/2020-10-15-detect_activity_related_to_pass_the_hash_attacks.md @@ -54,7 +54,7 @@ This search looks for specific authentication events from the Windows Security E ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md b/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md deleted file mode 100644 index 0c753e11af..0000000000 --- a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.md +++ /dev/null @@ -1,97 +0,0 @@ ---- -title: "Credential Extraction indicative of FGDump and CacheDump with s option" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-18 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is a newer version of pwdump tool that extracts NTLM and LanMan password hashes from Windows. Cachedump is a publicly-available tool that extracts cached password hashes from a system's registry. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-18 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 312582f2-5e91-42c1-a275-cd67f31373c8 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND process_name != null AND parent_process_name != null AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true AND match_regex(cmd_line, /(?i)\-s/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Unusual Processes](/stories/unusual_processes) -* [Credential Dumping](/stories/credential_dumping) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* process_name -* parent_process_name -* _time -* process_path -* dest_user_id -* process - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Malicious actor is accessing stored credentials via FGDump or CacheDump tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md b/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md deleted file mode 100644 index 7b5cfb6787..0000000000 --- a/docs/_posts/2020-10-18-credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.md +++ /dev/null @@ -1,96 +0,0 @@ ---- -title: "Credential Extraction indicative of FGDump and CacheDump with v option" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-18 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is a newer version of pwdump tool that extracts NTLM and LanMan password hashes from Windows. Cachedump is a publicly-available tool that extracts cached password hashes from a system's registry. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-18 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true AND match_regex(cmd_line, /(?i)\-v/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Unusual Processes](/stories/unusual_processes) -* [Credential Dumping](/stories/credential_dumping) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* process_name -* _time -* process_path -* dest_user_id -* process - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Malicious actor is accessing stored credentials via FGDump or CacheDump tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md b/docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md deleted file mode 100644 index 3e5ff7beae..0000000000 --- a/docs/_posts/2020-10-18-credential_extraction_indicative_of_lazagne_command_line_options.md +++ /dev/null @@ -1,97 +0,0 @@ ---- -title: "Credential Extraction indicative of Lazagne command line options" -excerpt: "OS Credential Dumping, Credentials from Password Stores" -categories: - - Endpoint -last_modified_at: 2020-10-18 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Credentials from Password Stores - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. LaZagne is a tool that extracts various kinds of credentials from a local computer, including account passwords, domain passwords, browser passwords, etc. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-18 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 341975fa-4ad0-4f01-9acc-df4f69742db7 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND match_regex(cmd_line, /(?i)all\s+\-oA\s+\-output/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Lazagne malware is extracting/decoding encoded credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_indicative_of_lazagne_command_line_options.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md b/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md deleted file mode 100644 index a0976476aa..0000000000 --- a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.md +++ /dev/null @@ -1,99 +0,0 @@ ---- -title: "Credential Extraction native Microsoft debuggers peek into the kernel" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-18 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential material directly from memory and process dumps. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-18 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: c20bb8ec-e1b0-4640-b0ef-3a4c54f8c112 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND parent_process_name != null AND process_name != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) -* [Unusual Processes](/stories/unusual_processes) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* process_name -* parent_process_name -* _time -* dest_device_id -* dest_user_id -* process - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -Although unlikely, using debuggers this way may be indicative of developers analyzing crash dumps of their code. Note, even for developers this is an unusual way of working on code - debuggers are mostly used to step through code, not analyze its crash dumps. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Malicious actor is extracting/decoding encoded credentials via Microsoft's native debugging tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29](https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md b/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md deleted file mode 100644 index ece42e02d0..0000000000 --- a/docs/_posts/2020-10-18-credential_extraction_native_microsoft_debuggers_via_z_command_line_option.md +++ /dev/null @@ -1,95 +0,0 @@ ---- -title: "Credential Extraction native Microsoft debuggers via z command line option" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-18 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential material directly from memory and process dumps. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-18 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: adc51a77-90c9-4358-b43c-f10dd1a27d05 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND process_name != null AND ( match_regex(process_name, /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, /(?i)\-z\s+/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) -* [Unusual Processes](/stories/unusual_processes) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* process_name -* _time -* dest_device_id -* dest_user_id -* process - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -Although unlikely, using debuggers this way may be indicative of developers analyzing crash dumps of their code. Note, even for developers this is an unusual way of working on code - debuggers are mostly used to step through code, not analyze its crash dumps. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Malicious actor is extracting/decoding encoded credentials via Microsoft's native debugging tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md b/docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md deleted file mode 100644 index 2fd4251640..0000000000 --- a/docs/_posts/2020-10-18-credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.md +++ /dev/null @@ -1,95 +0,0 @@ ---- -title: "Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-18 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit and DSInternals are common exploit APIs offering PowerShell modules for various exploits of Windows and Active Directory environments. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-18 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: e4f126b5-e6bc-4a5c-b1a8-d07bc6c4a49f - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND match_regex(cmd_line, /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\ -|]+/)=true - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | PowerSploit malware is accessing stored credentials via Get-ADDBAccount module. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md deleted file mode 100644 index 05b9f49483..0000000000 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.md +++ /dev/null @@ -1,100 +0,0 @@ ---- -title: "Credential Extraction indicative of use of DSInternals credential conversion modules" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-21 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals is a collection of PowerShell modules commonly employed in exploits. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-21 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-UnicodePassword/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* process_name -* parent_process_name -* _time -* process_path -* dest_user_id -* process - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | DSInternals tool kit is converting stolen credential material to a form applicable to authentications. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/MichaelGrafnetter/DSInternals](https://github.com/MichaelGrafnetter/DSInternals) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md deleted file mode 100644 index 1a8507d4b8..0000000000 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_dsinternals_modules.md +++ /dev/null @@ -1,100 +0,0 @@ ---- -title: "Credential Extraction indicative of use of DSInternals modules" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-21 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals is a collection of PowerShell modules commonly employed in exploits. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-21 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, /(?i)Get-SamPasswordPolicy/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* process_name -* parent_process_name -* _time -* process_path -* dest_user_id -* process - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | DSInternals tool kit is accessing sensitive credential material such as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/MichaelGrafnetter/DSInternals](https://github.com/MichaelGrafnetter/DSInternals) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_indicative_of_use_of_dsinternals_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md deleted file mode 100644 index 868a105408..0000000000 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_mimikatz_modules.md +++ /dev/null @@ -1,97 +0,0 @@ ---- -title: "Credential Extraction indicative of use of Mimikatz modules" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-21 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Mimikatz is a collection of tools and modules commonly employed in Windows exploits. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-21 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) -* [Unusual Processes](/stories/unusual_processes) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 66.5 | 70 | 95 | Mimikatz malware is extracting/decoding encoded credentials from stores such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_indicative_of_use_of_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md b/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md deleted file mode 100644 index c965264fec..0000000000 --- a/docs/_posts/2020-10-21-credential_extraction_indicative_of_use_of_powersploit_modules.md +++ /dev/null @@ -1,97 +0,0 @@ ---- -title: "Credential Extraction indicative of use of PowerSploit modules" -excerpt: "OS Credential Dumping" -categories: - - Endpoint -last_modified_at: 2020-10-21 -toc: true -toc_label: "" -tags: - - OS Credential Dumping - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit is a collection of Microsoft PowerShell modules commonly employed in exploits. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-10-21 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 5f1186a4-e681-446e-851c-dc9574ad28eb - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | PowerSploit malware is extracting encoded credentials or spoofing automated logings. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/credential_extraction_indicative_of_use_of_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md b/docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md deleted file mode 100644 index e5e5d64c3f..0000000000 --- a/docs/_posts/2020-11-03-applying_stolen_credentials_via_mimikatz_modules.md +++ /dev/null @@ -1,146 +0,0 @@ ---- -title: "Applying Stolen Credentials via Mimikatz modules" -excerpt: "Process Injection, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation, Access Token Manipulation, Create or Modify System Process, Boot or Logon Autostart Execution, Abuse Elevation Control Mechanism, Compromise Client Software Binary, Modify Authentication Process, Steal or Forge Kerberos Tickets" -categories: - - Endpoint -last_modified_at: 2020-11-03 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Exploitation for Privilege Escalation - - Privilege Escalation - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Access Token Manipulation - - Defense Evasion - - Privilege Escalation - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Abuse Elevation Control Mechanism - - Privilege Escalation - - Defense Evasion - - Compromise Client Software Binary - - Persistence - - Modify Authentication Process - - Credential Access - - Defense Evasion - - Persistence - - Steal or Forge Kerberos Tickets - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection indicates use of Mimikatz modules that facilitate Pass-the-Token attack, Golden or Silver kerberos ticket attack, and Skeleton key attack. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-03 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 759a653f-cb92-40f9-94c9-ec4e47b0f709 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -| [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - -| [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - -| [T1556](https://attack.mitre.org/techniques/T1556/) | Modify Authentication Process | Credential Access, Defense Evasion, Persistence | - -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | Mimikatz malware is violating authentication processes by injecting golden or silver Kerberos tickets or passing stolen authentication tokens. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) -* [https://adsecurity.org/?p=1275](https://adsecurity.org/?p=1275) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/applying_stolen_credentials_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md b/docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md deleted file mode 100644 index 7662d8a84b..0000000000 --- a/docs/_posts/2020-11-03-applying_stolen_credentials_via_powersploit_modules.md +++ /dev/null @@ -1,144 +0,0 @@ ---- -title: "Applying Stolen Credentials via PowerSploit modules" -excerpt: "Process Injection, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation, Access Token Manipulation, Create or Modify System Process, Boot or Logon Autostart Execution, Abuse Elevation Control Mechanism, Compromise Client Software Binary, Credentials from Password Stores, Steal or Forge Kerberos Tickets" -categories: - - Endpoint -last_modified_at: 2020-11-03 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Exploitation for Privilege Escalation - - Privilege Escalation - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Access Token Manipulation - - Defense Evasion - - Privilege Escalation - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Abuse Elevation Control Mechanism - - Privilege Escalation - - Defense Evasion - - Compromise Client Software Binary - - Persistence - - Credentials from Password Stores - - Credential Access - - Steal or Forge Kerberos Tickets - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -Stolen credentials are applied by methods such as user impersonation, credential injection, spoofing of authentication processes or getting hold of critical accounts. This detection indicates such activities carried out by PowerSploit exploit kit APIs. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-03 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 270b482d-2af2-448f-9923-9cf005f61be4 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -| [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - -| [T1554](https://attack.mitre.org/techniques/T1554/) | Compromise Client Software Binary | Persistence | - -| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - -| [T1558](https://attack.mitre.org/techniques/T1558/) | Steal or Forge Kerberos Tickets | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | PowerSploit malware is violating authentication by injecting stolen credentials, manipulating authentication tokens or impersonating system or user accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/applying_stolen_credentials_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md b/docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md deleted file mode 100644 index 1f45db9f7f..0000000000 --- a/docs/_posts/2020-11-03-assessment_of_credential_strength_via_dsinternals_modules.md +++ /dev/null @@ -1,118 +0,0 @@ ---- -title: "Assessment of Credential Strength via DSInternals modules" -excerpt: "Valid Accounts, Account Manipulation, Account Discovery, Password Policy Discovery, Unsecured Credentials, Credentials from Password Stores" -categories: - - Endpoint -last_modified_at: 2020-11-03 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Account Discovery - - Discovery - - Password Policy Discovery - - Discovery - - Unsecured Credentials - - Credential Access - - Credentials from Password Stores - - Credential Access - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of DSInternals modules that verify password strength, i.e., identify weak accounts that would be easily compromised. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-03 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1201](https://attack.mitre.org/techniques/T1201/) | Password Policy Discovery | Discovery | - -| [T1552](https://attack.mitre.org/techniques/T1552/) | Unsecured Credentials | Credential Access | - -| [T1555](https://attack.mitre.org/techniques/T1555/) | Credentials from Password Stores | Credential Access | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Test-PasswordQuality/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Credential Dumping](/stories/credential_dumping) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 25.5 | 30 | 85 | DSInternals tool kit is assessing password strength at the device $dest_device_id$. Account attempting this operation is $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/MichaelGrafnetter/DSInternals](https://github.com/MichaelGrafnetter/DSInternals) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/assessment_of_credential_strength_via_dsinternals_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md b/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md deleted file mode 100644 index cdf3b522db..0000000000 --- a/docs/_posts/2020-11-03-reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.md +++ /dev/null @@ -1,126 +0,0 @@ ---- -title: "Reconnaissance of Credential Stores and Services via Mimikatz modules" -excerpt: "Account Manipulation, Domain Properties, Valid Accounts, Credentials, Gather Victim Network Information, Exploitation for Privilege Escalation, Gather Victim Identity Information, Network Trust Dependencies" -categories: - - Endpoint -last_modified_at: 2020-11-03 -toc: true -toc_label: "" -tags: - - Account Manipulation - - Persistence - - Domain Properties - - Reconnaissance - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Credentials - - Reconnaissance - - Gather Victim Network Information - - Reconnaissance - - Exploitation for Privilege Escalation - - Privilege Escalation - - Gather Victim Identity Information - - Reconnaissance - - Network Trust Dependencies - - Reconnaissance - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies reconnaissance of credential stores and use of CryptoAPI services by Mimikatz modules. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-03 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 5facee5b-79e4-47ab-b0e6-c625acc0554f - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -| [T1590.001](https://attack.mitre.org/techniques/T1590/001/) | Domain Properties | Reconnaissance | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1589.001](https://attack.mitre.org/techniques/T1589/001/) | Credentials | Reconnaissance | - -| [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1589](https://attack.mitre.org/techniques/T1589/) | Gather Victim Identity Information | Reconnaissance | - -| [T1590.003](https://attack.mitre.org/techniques/T1590/003/) | Network Trust Dependencies | Reconnaissance | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Mimikatz malware is searching for and accessing credential stores. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md b/docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md deleted file mode 100644 index 515bdba702..0000000000 --- a/docs/_posts/2020-11-03-setting_credentials_via_dsinternals_modules.md +++ /dev/null @@ -1,110 +0,0 @@ ---- -title: "Setting Credentials via DSInternals modules" -excerpt: "Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation" -categories: - - Endpoint -last_modified_at: 2020-11-03 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies illegal setting of credentials via DSInternals modules. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-03 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* process_name -* parent_process_name -* _time -* process_path -* dest_user_id -* process - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | DSInternals malware is accessing, using or setting Active Directory or Azure credentials and accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/MichaelGrafnetter/DSInternals](https://github.com/MichaelGrafnetter/DSInternals) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/setting_credentials_via_dsinternals_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md b/docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md deleted file mode 100644 index e18e937edb..0000000000 --- a/docs/_posts/2020-11-03-setting_credentials_via_mimikatz_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Setting Credentials via Mimikatz modules" -excerpt: "Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation" -categories: - - Endpoint -last_modified_at: 2020-11-03 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies illegal setting of credentials via Mimikatz modules. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-03 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: c8b84699-7652-4363-910f-efd1ca82f780 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Mimikatz malware is accessing, using or setting account credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/setting_credentials_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md b/docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md deleted file mode 100644 index de67fb38fc..0000000000 --- a/docs/_posts/2020-11-03-setting_credentials_via_powersploit_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Setting Credentials via PowerSploit modules" -excerpt: "Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation" -categories: - - Endpoint -last_modified_at: 2020-11-03 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies illegal setting of credentials via PowerSploit modules. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-03 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 07b2a501-f967-4ddc-9f56-2dce46dfce44 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Set-DomainUserPassword/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | PowerSploit malware is setting passwords on Active Directory accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/setting_credentials_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md b/docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md deleted file mode 100644 index 6831faadb1..0000000000 --- a/docs/_posts/2020-11-04-probing_access_with_stolen_credentials_via_powersploit_modules.md +++ /dev/null @@ -1,102 +0,0 @@ ---- -title: "Probing Access with Stolen Credentials via PowerSploit modules" -excerpt: "Valid Accounts, Account Manipulation" -categories: - - Endpoint -last_modified_at: 2020-11-04 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of PowerSploit modules that facilitate access probing with admin credentials as well as probing access to system services. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-04 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: d405af5d-99f1-45af-8dfb-b8f98b764247 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_user_id -* dest_device_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 60 | 100 | PowerSploit malware is probing access with stolen credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/probing_access_with_stolen_credentials_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md b/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md deleted file mode 100644 index 38323a1cf8..0000000000 --- a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Reconnaissance and Access to Accounts and Groups via Mimikatz modules" -excerpt: "Valid Accounts, Account Discovery, Domain Policy Modification" -categories: - - Endpoint -last_modified_at: 2020-11-05 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Discovery - - Discovery - - Domain Policy Modification - - Defense Evasion - - Privilege Escalation - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of Mimikatz modules for discovery of accounts and groups and access to them. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-05 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | Mimikatz malware is searching for and using specific accounts and groups. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md deleted file mode 100644 index 61f382d90f..0000000000 --- a/docs/_posts/2020-11-05-reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules" -excerpt: "Valid Accounts, Account Discovery, Domain Policy Modification" -categories: - - Endpoint -last_modified_at: 2020-11-05 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Discovery - - Discovery - - Domain Policy Modification - - Defense Evasion - - Privilege Escalation - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that discover accounts, groups and policies that can be accessed or taken over. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-05 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 63422f8e-766c-468f-8133-2ba6795e263b - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -| [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, /(?i)Get-LastLoggedOn/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | PowerSploit malware is searching for and using specific accounts, groups and policies, such as the last logged on account, a local Net group, etc. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md deleted file mode 100644 index b289e12f8f..0000000000 --- a/docs/_posts/2020-11-05-reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.md +++ /dev/null @@ -1,124 +0,0 @@ ---- -title: "Reconnaissance of Access and Persistence Opportunities via PowerSploit modules" -excerpt: "Scheduled Task/Job, Exploitation for Privilege Escalation, Valid Accounts, Create or Modify System Process, Boot or Logon Autostart Execution, Hijack Execution Flow" -categories: - - Endpoint -last_modified_at: 2020-11-05 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Exploitation for Privilege Escalation - - Privilege Escalation - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Boot or Logon Autostart Execution - - Persistence - - Privilege Escalation - - Hijack Execution Flow - - Persistence - - Privilege Escalation - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of PowerSploit modules that discover opportunities for malicious access and persistence. Some examples include access to admin accounts, weak access control policies, landing paths for dropping malicious software or data to exfiltrate, registry locations to land autorun parameters, task scheduling opportunities, as well as services and system files that can be compromised. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-05 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1547](https://attack.mitre.org/techniques/T1547/) | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | - -| [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, /(?i)Get-UnquotedService/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 60 | 100 | PowerSploit malware is searching for an entry point into the infrastructure, such as local admin accounts, opportunities to hijack processes, unattended install files, or modifiable access objects. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md deleted file mode 100644 index 2080b849c8..0000000000 --- a/docs/_posts/2020-11-05-reconnaissance_of_defensive_tools_via_powersploit_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Reconnaissance of Defensive Tools via PowerSploit modules" -excerpt: "Software, Vulnerability Scanning, Gather Victim Host Information, Active Scanning" -categories: - - Endpoint -last_modified_at: 2020-11-05 -toc: true -toc_label: "" -tags: - - Software - - Reconnaissance - - Vulnerability Scanning - - Reconnaissance - - Gather Victim Host Information - - Reconnaissance - - Active Scanning - - Reconnaissance - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of PowerSploit modules for assessment of presence of defensive tools. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-05 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 24b4e659-63a2-4e7b-89ac-87dd659c7110 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance | - -| [T1595.002](https://attack.mitre.org/techniques/T1595/002/) | Vulnerability Scanning | Reconnaissance | - -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -| [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-AVSignature/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 40.0 | 40 | 100 | PowerSploit malware is looking for presence of anti virus software. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_of_defensive_tools_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md deleted file mode 100644 index 02ee11f4b3..0000000000 --- a/docs/_posts/2020-11-05-reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.md +++ /dev/null @@ -1,106 +0,0 @@ ---- -title: "Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules" -excerpt: "Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation" -categories: - - Endpoint -last_modified_at: 2020-11-05 -toc: true -toc_label: "" -tags: - - Exploitation for Privilege Escalation - - Privilege Escalation - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of PowerSploit modules for assessment of privilege escalation opportunities. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-05 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: b9b4492c-2af8-449b-beb4-b1b78d963321 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Privilege Escalation | - -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Invoke-PrivescAudit/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 60.0 | 60 | 100 | PowerSploit malware is engaging its privilege escalation module. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md b/docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md deleted file mode 100644 index edd9e9cc37..0000000000 --- a/docs/_posts/2020-11-05-reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.md +++ /dev/null @@ -1,108 +0,0 @@ ---- -title: "Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules" -excerpt: "Create or Modify System Process, Process Injection, Hijack Execution Flow" -categories: - - Endpoint -last_modified_at: 2020-11-05 -toc: true -toc_label: "" -tags: - - Create or Modify System Process - - Persistence - - Privilege Escalation - - Process Injection - - Defense Evasion - - Privilege Escalation - - Hijack Execution Flow - - Persistence - - Privilege Escalation - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of Mimikatz modules for discovery of process or service hijacking opportunities via Microsoft Detours compatibility. Microsoft Detours is an open source library for intercepting, monitoring and instrumenting binary functions on Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory code for target functions. The Detours package also contains utilities to attach arbitrary DLLs and data segments called payloads to any Win32 binary. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-05 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: fc5c1cbd-7494-4314-aad2-458d6fd4fada - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | - -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1574](https://attack.mitre.org/techniques/T1574/) | Hijack Execution Flow | Persistence, Privilege Escalation, Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)misc::detours/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Mimikatz malware is looking for and invoking Microsoft Detours package that enables spoofing of in-memory code. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) -* [https://en.wikipedia.org/wiki/Microsoft_Detours](https://en.wikipedia.org/wiki/Microsoft_Detours) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md deleted file mode 100644 index 298d99ad17..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.md +++ /dev/null @@ -1,111 +0,0 @@ ---- -title: "Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules" -excerpt: "Trusted Relationship, Domain Trust Discovery, Gather Victim Network Information, Gather Victim Org Information, Active Scanning" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Trusted Relationship - - Initial Access - - Domain Trust Discovery - - Discovery - - Gather Victim Network Information - - Reconnaissance - - Gather Victim Org Information - - Reconnaissance - - Active Scanning - - Reconnaissance - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules for reconnaissance and access to elements of Active Directory infrastructure, such as domain identifiers, AD sites and forests, and trust relations. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: db08ac40-ee14-43e9-9a75-dddd059ef812 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1199](https://attack.mitre.org/techniques/T1199/) | Trusted Relationship | Initial Access | - -| [T1482](https://attack.mitre.org/techniques/T1482/) | Domain Trust Discovery | Discovery | - -| [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - -| [T1591](https://attack.mitre.org/techniques/T1591/) | Gather Victim Org Information | Reconnaissance | - -| [T1595](https://attack.mitre.org/techniques/T1595/) | Active Scanning | Reconnaissance | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | PowerSploit malware is seaching for or accessing Active Directory objects such as domain sites, domain trusts, AD forests, etc. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md deleted file mode 100644 index 1698ca8885..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.md +++ /dev/null @@ -1,103 +0,0 @@ ---- -title: "Reconnaissance and Access to Computers and Domains via PowerSploit modules" -excerpt: "Gather Victim Host Information, Gather Victim Network Information, Account Discovery" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Gather Victim Network Information - - Reconnaissance - - Account Discovery - - Discovery - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that discover computers, servers and domains that can be accessed or taken over. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: fe1c4c5a-09f3-4b43-8129-560a7f38a08b - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -| [T1590](https://attack.mitre.org/techniques/T1590/) | Gather Victim Network Information | Reconnaissance | - -| [T1087](https://attack.mitre.org/techniques/T1087/) | Account Discovery | Discovery | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | PowerSploit malware is seaching for or accessing domain controllers, computers, file servers, etc. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md deleted file mode 100644 index d86240f486..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_computers_via_mimikatz_modules.md +++ /dev/null @@ -1,95 +0,0 @@ ---- -title: "Reconnaissance and Access to Computers via Mimikatz modules" -excerpt: "Gather Victim Host Information" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Gather Victim Host Information - - Reconnaissance - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of Mimikatz modules for discovery of computers and servers and access to them. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::ServerInfo/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 50 | 100 | Mimikatz malware is collecting information about computers. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_computers_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md deleted file mode 100644 index 3f9d89b415..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.md +++ /dev/null @@ -1,127 +0,0 @@ ---- -title: "Reconnaissance and Access to Operating System Elements via PowerSploit modules" -excerpt: "Process Discovery, File and Directory Discovery, Software, Network Service Scanning, Query Registry, System Service Discovery, Windows Management Instrumentation, Gather Victim Host Information, Software Discovery" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Process Discovery - - Discovery - - File and Directory Discovery - - Discovery - - Software - - Reconnaissance - - Network Service Scanning - - Discovery - - Query Registry - - Discovery - - System Service Discovery - - Discovery - - Windows Management Instrumentation - - Execution - - Gather Victim Host Information - - Reconnaissance - - Software Discovery - - Discovery - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that discover and access operating system elements, such as processes, services, registry locations, security packages and files. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: c1d33ad9-1727-4f9f-a474-4adbe4fed68a - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1057](https://attack.mitre.org/techniques/T1057/) | Process Discovery | Discovery | - -| [T1083](https://attack.mitre.org/techniques/T1083/) | File and Directory Discovery | Discovery | - -| [T1592.002](https://attack.mitre.org/techniques/T1592/002/) | Software | Reconnaissance | - -| [T1046](https://attack.mitre.org/techniques/T1046/) | Network Service Scanning | Discovery | - -| [T1012](https://attack.mitre.org/techniques/T1012/) | Query Registry | Discovery | - -| [T1007](https://attack.mitre.org/techniques/T1007/) | System Service Discovery | Discovery | - -| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | - -| [T1592](https://attack.mitre.org/techniques/T1592/) | Gather Victim Host Information | Reconnaissance | - -| [T1518](https://attack.mitre.org/techniques/T1518/) | Software Discovery | Discovery | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, /(?i)Get-RegistryMountedDrive/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | PowerSploit malware is searching for and tapping into ongoing processes, mounted drives or other operating system elements. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md deleted file mode 100644 index 6718a0d813..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.md +++ /dev/null @@ -1,103 +0,0 @@ ---- -title: "Reconnaissance and Access to Processes and Services via Mimikatz modules" -excerpt: "System Service Discovery, Network Service Scanning, Process Discovery" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - System Service Discovery - - Discovery - - Network Service Scanning - - Discovery - - Process Discovery - - Discovery - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of Mimikatz modules for discovery and access to services and processes. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 0243d37c-57c1-4182-bfd1-39b212255fc8 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1007](https://attack.mitre.org/techniques/T1007/) | System Service Discovery | Discovery | - -| [T1046](https://attack.mitre.org/techniques/T1046/) | Network Service Scanning | Discovery | - -| [T1057](https://attack.mitre.org/techniques/T1057/) | Process Discovery | Discovery | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 50 | 100 | Mimikatz malware is listing processes and services. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md deleted file mode 100644 index 9861d5d898..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Reconnaissance and Access to Shared Resources via Mimikatz modules" -excerpt: "Remote Services, Data from Network Shared Drive, Network Share Discovery, SMB/Windows Admin Shares" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Remote Services - - Lateral Movement - - Data from Network Shared Drive - - Collection - - Network Share Discovery - - Discovery - - SMB/Windows Admin Shares - - Lateral Movement - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of Mimikatz modules for discovery and access to network shares. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - -| [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | - -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::share/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Mimikatz malware is searching for and accessing network shares. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md deleted file mode 100644 index 9a7a3425b7..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_and_access_to_shared_resources_via_powersploit_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Reconnaissance and Access to Shared Resources via PowerSploit modules" -excerpt: "Remote Services, Data from Network Shared Drive, Network Share Discovery, SMB/Windows Admin Shares" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Remote Services - - Lateral Movement - - Data from Network Shared Drive - - Collection - - Network Share Discovery - - Discovery - - SMB/Windows Admin Shares - - Lateral Movement - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that discover and access network and distributed file system shares. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 6b7ca431-6b1e-4b40-9589-21cb368e369e - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - -| [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | - -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | PowerSploit malware is searching for and accessing network shares. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md b/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md deleted file mode 100644 index a36fb00db4..0000000000 --- a/docs/_posts/2020-11-06-reconnaissance_of_connectivity_via_powersploit_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Reconnaissance of Connectivity via PowerSploit modules" -excerpt: "Remote Services, Data from Network Shared Drive, Network Share Discovery, SMB/Windows Admin Shares" -categories: - - Endpoint -last_modified_at: 2020-11-06 -toc: true -toc_label: "" -tags: - - Remote Services - - Lateral Movement - - Data from Network Shared Drive - - Collection - - Network Share Discovery - - Discovery - - SMB/Windows Admin Shares - - Lateral Movement - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules for reconnaissance of connectivity. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-06 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1039](https://attack.mitre.org/techniques/T1039/) | Data from Network Shared Drive | Collection | - -| [T1135](https://attack.mitre.org/techniques/T1135/) | Network Share Discovery | Discovery | - -| [T1021.002](https://attack.mitre.org/techniques/T1021/002/) | SMB/Windows Admin Shares | Lateral Movement | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Discovery Techniques](/stories/windows_discovery_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* _time -* process -* dest_device_id -* dest_user_id - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | PowerSploit malware is performing port scans or searching for various connectivity details such as DNS data, proxies, or ongoing RDP connections. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/reconnaissance_of_connectivity_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md deleted file mode 100644 index 798884a058..0000000000 --- a/docs/_posts/2020-11-09-illegal_access_to_user_content_via_powersploit_modules.md +++ /dev/null @@ -1,108 +0,0 @@ ---- -title: "Illegal Access To User Content via PowerSploit modules" -excerpt: "Remote Services, Screen Capture, Audio Capture, Remote Service Session Hijacking" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Remote Services - - Lateral Movement - - Screen Capture - - Collection - - Audio Capture - - Collection - - Remote Service Session Hijacking - - Lateral Movement - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that enable illegaly access user content, such as key logging, audio recording, screenshots, tapping into http and RDP sessions, etc. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 01fc7d91-eb0c-478e-8633-e4fa4904463a - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | - -| [T1113](https://attack.mitre.org/techniques/T1113/) | Screen Capture | Collection | - -| [T1123](https://attack.mitre.org/techniques/T1123/) | Audio Capture | Collection | - -| [T1563](https://attack.mitre.org/techniques/T1563/) | Remote Service Session Hijacking | Lateral Movement | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, /(?i)Get-WebConfig/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 85.0 | 85 | 100 | PowerSploit malware is tapping into user content - microphone, camera, ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_access_to_user_content_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md deleted file mode 100644 index 8b45cd7d45..0000000000 --- a/docs/_posts/2020-11-09-illegal_account_creation_via_powersploit_modules.md +++ /dev/null @@ -1,96 +0,0 @@ ---- -title: "Illegal Account Creation via PowerSploit modules" -excerpt: "Establish Accounts" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Establish Accounts - - Resource Development - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that create accounts illegaly. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 20fba62a-fa5b-46cc-b39f-473fa248fee2 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1585](https://attack.mitre.org/techniques/T1585/) | Establish Accounts | Resource Development | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)New-DomainUser/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | PowerSploit malware is creating illegal domain accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_account_creation_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md b/docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md deleted file mode 100644 index c5951dda6d..0000000000 --- a/docs/_posts/2020-11-09-illegal_deletion_of_logs_via_mimikatz_modules.md +++ /dev/null @@ -1,96 +0,0 @@ ---- -title: "Illegal Deletion of Logs via Mimikatz modules" -excerpt: "Indicator Removal on Host" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Indicator Removal on Host - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that delete event logs. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Log Manipulation](/stories/windows_log_manipulation) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 50.0 | 50 | 100 | Mimikatz malware is deleting event logs to cover tracks of malicious activity. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_deletion_of_logs_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md b/docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md deleted file mode 100644 index 249ca5ec3a..0000000000 --- a/docs/_posts/2020-11-09-illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.md +++ /dev/null @@ -1,103 +0,0 @@ ---- -title: "Illegal Enabling or Disabling of Accounts via DSInternals modules" -excerpt: "Valid Accounts, Account Manipulation" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Valid Accounts - - Defense Evasion - - Persistence - - Privilege Escalation - - Initial Access - - Account Manipulation - - Persistence - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of DSInternals modules that enable or disable accounts illegaly. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 3e0f9962-9989-445f-878c-939443326b63 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | - -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 80.0 | 80 | 100 | DSInternals malware is illegally enabling or disabling accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/MichaelGrafnetter/DSInternals](https://github.com/MichaelGrafnetter/DSInternals) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md b/docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md deleted file mode 100644 index b0798af130..0000000000 --- a/docs/_posts/2020-11-09-illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.md +++ /dev/null @@ -1,105 +0,0 @@ ---- -title: "Illegal Management of Active Directory Elements and Policies via DSInternals modules" -excerpt: "Account Manipulation, Rogue Domain Controller, Domain Policy Modification" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Account Manipulation - - Persistence - - Rogue Domain Controller - - Defense Evasion - - Domain Policy Modification - - Defense Evasion - - Privilege Escalation - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of DSInternals modules for illegal management of Active Directoty elements and policies. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: a587ca9f-c138-47b4-ba51-699f319b8cc5 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -| [T1207](https://attack.mitre.org/techniques/T1207/) | Rogue Domain Controller | Defense Evasion | - -| [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, /(?i)Set-LsaPolicyInformation/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | DSInternals malware is controlling infrastructure by modifying Active Directory elements, domain controllers, and policies. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/MichaelGrafnetter/DSInternals](https://github.com/MichaelGrafnetter/DSInternals) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md deleted file mode 100644 index f602464520..0000000000 --- a/docs/_posts/2020-11-09-illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.md +++ /dev/null @@ -1,106 +0,0 @@ ---- -title: "Illegal Management of Computers and Active Directory Elements via PowerSploit modules" -excerpt: "Account Manipulation, Rogue Domain Controller, Domain Policy Modification" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Account Manipulation - - Persistence - - Rogue Domain Controller - - Defense Evasion - - Domain Policy Modification - - Defense Evasion - - Privilege Escalation - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that enable illegal management of computers and Active Directory elements. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 75760c11-7d48-4968-b828-013b299e8f6d - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1098](https://attack.mitre.org/techniques/T1098/) | Account Manipulation | Persistence | - -| [T1207](https://attack.mitre.org/techniques/T1207/) | Rogue Domain Controller | Defense Evasion | - -| [T1484](https://attack.mitre.org/techniques/T1484/) | Domain Policy Modification | Defense Evasion, Privilege Escalation | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, /(?i)Set-MasterBootRecord/)=true ) - - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | PowerSploit malware is controlling infrastructure by modifying Active Directory elements or local Master Boot Records. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md deleted file mode 100644 index 92e607770e..0000000000 --- a/docs/_posts/2020-11-09-illegal_privilege_elevation_and_persistence_via_powersploit_modules.md +++ /dev/null @@ -1,109 +0,0 @@ ---- -title: "Illegal Privilege Elevation and Persistence via PowerSploit modules" -excerpt: "Scheduled Task/Job, Access Token Manipulation, Abuse Elevation Control Mechanism" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Scheduled Task/Job - - Execution - - Persistence - - Privilege Escalation - - Access Token Manipulation - - Defense Evasion - - Privilege Escalation - - Abuse Elevation Control Mechanism - - Privilege Escalation - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that illegaly elevate general privileges or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent WMI, access to OS objects under desired identities. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 88c10ee9-fe72-4bce-b343-5b129044b991 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | - -| [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Malicious PowerShell](/stories/malicious_powershell) -* [Windows Persistence Techniques](/stories/windows_persistence_techniques) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | PowerSploit malware is planting attack persistence elements, altering privileges and access controls. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md b/docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md deleted file mode 100644 index 9f96e8c8b5..0000000000 --- a/docs/_posts/2020-11-09-illegal_privilege_elevation_via_mimikatz_modules.md +++ /dev/null @@ -1,102 +0,0 @@ ---- -title: "Illegal Privilege Elevation via Mimikatz modules" -excerpt: "Access Token Manipulation, Abuse Elevation Control Mechanism" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Access Token Manipulation - - Defense Evasion - - Privilege Escalation - - Abuse Elevation Control Mechanism - - Privilege Escalation - - Defense Evasion - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of Mimikatz modules for illegal privilege elevation. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 2f873b1f-6352-4844-b7b9-b419f09a42c7 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1134](https://attack.mitre.org/techniques/T1134/) | Access Token Manipulation | Defense Evasion, Privilege Escalation | - -| [T1548](https://attack.mitre.org/techniques/T1548/) | Abuse Elevation Control Mechanism | Privilege Escalation, Defense Evasion | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Privilege Escalation](/stories/windows_privilege_escalation) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | Mimikatz malware is setting highest privileges to malicious entities. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_privilege_elevation_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md b/docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md deleted file mode 100644 index 0e5b72a9b1..0000000000 --- a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_mimikatz_modules.md +++ /dev/null @@ -1,105 +0,0 @@ ---- -title: "Illegal Service and Process Control via Mimikatz modules" -excerpt: "Process Injection, Native API, System Services" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Native API - - Execution - - System Services - - Execution - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies use of Mimikatz modules for illegal control over services and processes, including the authentication service. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: aaf3adf1-73e1-4477-b4ee-3771898964f1 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1106](https://attack.mitre.org/techniques/T1106/) | Native API | Execution | - -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Service Abuse](/stories/windows_service_abuse) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | Mimikatz malware is controlling computer's processess and services. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_service_and_process_control_via_mimikatz_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md b/docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md deleted file mode 100644 index 557f4b76cc..0000000000 --- a/docs/_posts/2020-11-09-illegal_service_and_process_control_via_powersploit_modules.md +++ /dev/null @@ -1,107 +0,0 @@ ---- -title: "Illegal Service and Process Control via PowerSploit modules" -excerpt: "Process Injection, Native API, System Services" -categories: - - Endpoint -last_modified_at: 2020-11-09 -toc: true -toc_label: "" -tags: - - Process Injection - - Defense Evasion - - Privilege Escalation - - Native API - - Execution - - System Services - - Execution - - Splunk Behavioral Analytics - - Endpoint_Processes ---- - - - -[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} - -#### Description - -This detection identifies access to PowerSploit modules that enable illegal control of services and processes, such as installing or spoofing of malicious services, injecting malicious code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to service objects, etc. - -- **Type**: TTP -- **Product**: Splunk Behavioral Analytics -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-11-09 -- **Author**: Stanislav Miskovic, Splunk -- **ID**: 0e910e5b-309d-4bc3-8af2-0030c02aa353 - - -#### [ATT&CK](https://attack.mitre.org/) - -| ID | Technique | Tactic | -| ----------- | ----------- |--------------- | -| [T1055](https://attack.mitre.org/techniques/T1055/) | Process Injection | Defense Evasion, Privilege Escalation | - -| [T1106](https://attack.mitre.org/techniques/T1106/) | Native API | Execution | - -| [T1569](https://attack.mitre.org/techniques/T1569/) | System Services | Execution | - -#### Search - -``` - -| from read_ssa_enriched_events() - -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line != null AND ( match_regex(cmd_line, /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true ) - - -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) -| into write_ssa_detected_events(); -``` - -#### Associated Analytic Story -* [Windows Service Abuse](/stories/windows_service_abuse) -* [Malicious PowerShell](/stories/malicious_powershell) - - -#### How To Implement -You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. - -#### Required field -* dest_device_id -* dest_user_id -* process -* _time - - -#### Kill Chain Phase -* Actions on Objectives - - -#### Known False Positives -None identified. - - -#### RBA - -| Risk Score | Impact | Confidence | Message | -| ----------- | ----------- |--------------|--------------| -| 90.0 | 90 | 100 | PowerSploit malware is controlling computer's processess and services. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | - - - - -#### Reference - -* [https://github.com/PowerShellMafia/PowerSploit](https://github.com/PowerShellMafia/PowerSploit) - - - -#### Test Dataset -Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). -Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) - -* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log) - - - -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/illegal_service_and_process_control_via_powersploit_modules.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md index bb2573303a..85e1259091 100644 --- a/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md +++ b/docs/_posts/2020-11-10-detect_prohibited_applications_spawning_cmd_exe.md @@ -19,7 +19,7 @@ tags: #### Description -The following analytic identifies parent processes, browsers, Windows terminal applications, Office Products and Java spawning cmd.exe. By its very nature, many applications spawn cmd.exe natively or built into macros. Much of this will need to be tuned to further enhance the risk. During triage, review parallel process execution and identify any file modifications that may have occurred. Capture any artifacts and review further. +The following analytic identifies parent processes, browsers, Windows terminal applications, Office Products and Java spawning cmd.exe. By its very nature, many applications spawn cmd.exe natively or built into macros. Much of this will need to be tuned to further enhance the risk. - **Type**: Anomaly - **Product**: Splunk Behavioral Analytics @@ -39,8 +39,8 @@ The following analytic identifies parent processes, browsers, Windows terminal a ``` -| from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) +| from read_ssa_enriched_events() + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) | eval process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"),"string", null)), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), event_id=ucast(map_get(input_event,"event_id"), "string", null) | where process_name="cmd.exe" @@ -63,6 +63,7 @@ In order to successfully implement this analytic, you will need endpoint process * _time * dest_device_id * dest_user_id +* cmd_line #### Kill Chain Phase diff --git a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md index e514ffca5f..0d6b7fcb84 100644 --- a/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md +++ b/docs/_posts/2021-04-08-winevent_scheduled_task_created_within_public_path.md @@ -65,7 +65,7 @@ Upon triage, identify the task scheduled source. Was it schtasks.exe or was it v * [Ransomware](/stories/ransomware) * [Ryuk Ransomware](/stories/ryuk_ransomware) * [IcedID](/stories/icedid) -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-09-14-net_localgroup_discovery.md b/docs/_posts/2021-09-14-net_localgroup_discovery.md index f8ce88b584..ab7409816a 100644 --- a/docs/_posts/2021-09-14-net_localgroup_discovery.md +++ b/docs/_posts/2021-09-14-net_localgroup_discovery.md @@ -54,6 +54,7 @@ The following hunting analytic will identify the use of localgroup discovery usi #### Associated Analytic Story * [Active Directory Discovery](/stories/active_directory_discovery) +* [Windows Discovery Techniques](/stories/windows_discovery_techniques) #### How To Implement diff --git a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md index 2d862de642..ffa9b39e6b 100644 --- a/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md +++ b/docs/_posts/2021-09-16-detect_psexec_with_accepteula_flag.md @@ -57,7 +57,7 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla * [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) * [HAFNIUM Group](/stories/hafnium_group) * [DarkSide Ransomware](/stories/darkside_ransomware) -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-09-16-detect_renamed_psexec.md b/docs/_posts/2021-09-16-detect_renamed_psexec.md index e793219766..c559d818e2 100644 --- a/docs/_posts/2021-09-16-detect_renamed_psexec.md +++ b/docs/_posts/2021-09-16-detect_renamed_psexec.md @@ -57,7 +57,7 @@ The following analytic identifies renamed instances of `PsExec.exe` being utiliz * [DHS Report TA18-074A](/stories/dhs_report_ta18-074a) * [HAFNIUM Group](/stories/hafnium_group) * [DarkSide Ransomware](/stories/darkside_ransomware) -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md b/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md index a6e0263361..b0c1cd09eb 100644 --- a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md +++ b/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.md @@ -23,7 +23,7 @@ tags: #### Description -This detection identifies potential Pass the Token or Pass the Hash credential exploits. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by an event-collecting device (i.e., a specific domain controller or an endpoint destination). +This detection identifies potential Pass the Token or Pass the Hash credential stealing. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by an event-collecting device (i.e., a specific domain controller or an endpoint destination). - **Type**: TTP - **Product**: Splunk Behavioral Analytics @@ -48,8 +48,7 @@ This detection identifies potential Pass the Token or Pass the Hash credential e | from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)) - +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND origin_device_id != null | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) @@ -58,13 +57,13 @@ This detection identifies potential Pass the Token or Pass the Hash credential e | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) -| eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, origin_device_id), body=create_map(["total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) +| eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, origin_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) | into write_ssa_detected_events(); ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement @@ -99,6 +98,7 @@ Environments in which NTLM is used extremely rarely and for benign purposes (suc #### Reference * [https://attack.mitre.org/techniques/T1550/002/](https://attack.mitre.org/techniques/T1550/002/) +* [https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/](https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/) diff --git a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md index c86d456b9d..c8881950c4 100644 --- a/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md +++ b/docs/_posts/2021-11-10-windows_service_creation_on_remote_endpoint.md @@ -55,7 +55,7 @@ This analytic looks for the execution of `sc.exe` with command-line arguments ut ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md index 2f55c50da1..c54c9dd691 100644 --- a/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md +++ b/docs/_posts/2021-11-10-windows_service_initiation_on_remote_endpoint.md @@ -55,7 +55,7 @@ This analytic looks for the execution of `sc.exe` with command-line arguments ut ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md b/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md index d0cd21c0cb..31a0ab74ab 100644 --- a/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md +++ b/docs/_posts/2021-11-11-remote_process_instantiation_via_winrm_and_winrs.md @@ -53,7 +53,7 @@ This analytic looks for the execution of `winrs.exe` with command-line arguments ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md b/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md index d6deb640a8..01f078dbc3 100644 --- a/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md +++ b/docs/_posts/2021-11-11-scheduled_task_creation_on_remote_endpoint_using_at.md @@ -57,7 +57,7 @@ This analytic looks for the execution of `at.exe` with command-line arguments ut ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md b/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md index f8cd74d201..4194118136 100644 --- a/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md +++ b/docs/_posts/2021-11-11-scheduled_task_initiation_on_remote_endpoint.md @@ -57,7 +57,7 @@ This analytic looks for the execution of `schtasks.exe` with command-line argume ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md b/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md index 59efd231dc..f559199a58 100644 --- a/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md +++ b/docs/_posts/2021-11-11-schtasks_scheduling_job_on_remote_system.md @@ -57,7 +57,7 @@ This analytic looks for the execution of `schtasks.exe` with command-line argume ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) * [NOBELIUM Group](/stories/nobelium_group) diff --git a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md index 50db93da97..238195e276 100644 --- a/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md +++ b/docs/_posts/2021-11-12-remote_process_instantiation_via_wmi.md @@ -51,7 +51,7 @@ This analytic identifies wmic.exe being launched with parameters to spawn a proc #### Associated Analytic Story * [Ransomware](/stories/ransomware) * [Suspicious WMI Use](/stories/suspicious_wmi_use) -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md index 0d4a4a1324..9f589e136e 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell.md @@ -53,7 +53,7 @@ This analytic looks for the execution of `powershell.exe` with arguments utilize ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md index 47d36b400a..0e27b62f7b 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_dcom_and_powershell_script_block.md @@ -51,7 +51,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md index 071a365db9..b585ba940b 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell.md @@ -49,7 +49,7 @@ This analytic looks for the execution of `powershell.exe` leveraging the `Invoke ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md index 9ad76f44fd..bbc7e7b397 100644 --- a/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md +++ b/docs/_posts/2021-11-15-remote_process_instantiation_via_wmi_and_powershell_script_block.md @@ -47,7 +47,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-15-sdelete_application_execution.md b/docs/_posts/2021-11-15-sdelete_application_execution.md index fb41e20dc2..9ba2baca55 100644 --- a/docs/_posts/2021-11-15-sdelete_application_execution.md +++ b/docs/_posts/2021-11-15-sdelete_application_execution.md @@ -71,6 +71,7 @@ To successfully implement this search you need to be ingesting information on pr * process * process_id * process_path +* cmd_line #### Kill Chain Phase @@ -85,7 +86,7 @@ False positives should be limited, filter as needed. | Risk Score | Impact | Confidence | Message | | ----------- | ----------- |--------------|--------------| -| 42.0 | 60 | 70 | sdelete process $process_name$ executed on $dest$ attempting to permanently delete files. | +| 42.0 | 60 | 70 | Sdelete process $process_name$ executed on $dest_device_id$ attempting to permanently delete files by $dest_user_id$. | diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md index 99ed49b5b0..a0528ae02e 100644 --- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md +++ b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell.md @@ -53,7 +53,7 @@ This analytic looks for the execution of `powershell.exe` with arguments utilize ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md index 8cf1485a31..cc6954a6d2 100644 --- a/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md +++ b/docs/_posts/2021-11-16-remote_process_instantiation_via_winrm_and_powershell_script_block.md @@ -51,7 +51,7 @@ The following analytic utilizes PowerShell Script Block Logging (EventCode=4104) ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md index 64058d3c54..cf1e2b17a3 100644 --- a/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md +++ b/docs/_posts/2021-11-18-executable_file_written_in_administrative_smb_share.md @@ -23,7 +23,7 @@ tags: #### Description -The following analytic identifies executable files (.exe or .dll) being written to Windows administrative SMB shares (Admin$, IPC$, C$). This represents suspicious behavior as its commonly user by tools like like PsExec/PaExec and others to stage service binaries before creating and starting a Windows service on remote endpoints. Red Teams and adversaries alike may abuse administrative shares for lateral movement and remote code execution. The Trickbot malware family also implements this behavior to try to infect other machines in the infected network. +The following analytic identifies executable files (.exe or .dll) being written to Windows administrative SMB shares (Admin$, IPC$, C$). This represents suspicious behavior as its commonly used by tools like like PsExec/PaExec and others to stage service binaries before creating and starting a Windows service on remote endpoints. Red Teams and adversaries alike may abuse administrative shares for lateral movement and remote code execution. The Trickbot malware family also implements this behavior to try to infect other machines in the infected network. - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud @@ -52,7 +52,7 @@ The following analytic identifies executable files (.exe or .dll) being written ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) * [Trickbot](/stories/trickbot) diff --git a/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md b/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md index ead98f1603..1baffcbf08 100644 --- a/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md +++ b/docs/_posts/2021-11-18-interactive_session_on_remote_endpoint_with_powershell.md @@ -51,7 +51,7 @@ powershell` EventCode=4104 (Message="*Enter-PSSession*" AND Message="*-ComputerN ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-19-impacket_lateral_movement_commandline_parameters.md b/docs/_posts/2021-11-19-impacket_lateral_movement_commandline_parameters.md index 1d53001c7e..822c336296 100644 --- a/docs/_posts/2021-11-19-impacket_lateral_movement_commandline_parameters.md +++ b/docs/_posts/2021-11-19-impacket_lateral_movement_commandline_parameters.md @@ -66,7 +66,7 @@ This analytic looks for the presence of suspicious commandline parameters typica ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md index 4317744ef1..49092854d7 100644 --- a/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-services_lolbas_execution_process_spawn.md @@ -25,7 +25,7 @@ tags: #### Description -The following analytic identifies `services.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Service Control Manager and creating a remote malicious service, the executed command is spawned as a child processs of `services.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of services.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. +The following analytic identifies `services.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Service Control Manager and creating a remote malicious service, the executed command is spawned as a child process of `services.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of services.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud @@ -55,7 +55,7 @@ The following analytic identifies `services.exe` spawning a LOLBAS execution pro ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md index 6a2b502972..8ed556304b 100644 --- a/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-svchost_lolbas_execution_process_spawn.md @@ -27,7 +27,7 @@ tags: #### Description -The following analytic identifies `svchost.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Task Scheduler and creating a malicious remote scheduled task, the executed command is spawned as a child processs of `svchost.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of svchost.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. +The following analytic identifies `svchost.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Task Scheduler and creating a malicious remote scheduled task, the executed command is spawned as a child process of `svchost.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of svchost.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud @@ -57,7 +57,7 @@ The following analytic identifies `svchost.exe` spawning a LOLBAS execution proc ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md index 5496712e16..563114b12c 100644 --- a/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md +++ b/docs/_posts/2021-11-22-windows_service_created_with_suspicious_service_path.md @@ -53,7 +53,7 @@ The following analytc uses Windows Event Id 7045, `New Service Was Installed`, t #### Associated Analytic Story * [Clop Ransomware](/stories/clop_ransomware) -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md index f42fea33f8..90991cd448 100644 --- a/docs/_posts/2021-11-22-windows_service_created_within_public_path.md +++ b/docs/_posts/2021-11-22-windows_service_created_within_public_path.md @@ -54,7 +54,7 @@ The following analytc uses Windows Event Id 7045, `New Service Was Installed`, t ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md index 6c72ff16bb..c4002edec9 100644 --- a/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-wmiprsve_lolbas_execution_process_spawn.md @@ -21,7 +21,7 @@ tags: #### Description -The following analytic identifies `wmiprsve.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing Windows Management Instrumention (WMI), the executed command is spawned as a child processs of `wmiprvse.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of wmiprvse.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. +The following analytic identifies `wmiprsve.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing Windows Management Instrumentation (WMI), the executed command is spawned as a child process of `wmiprvse.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of wmiprvse.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. - **Type**: TTP - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud @@ -49,7 +49,7 @@ The following analytic identifies `wmiprsve.exe` spawning a LOLBAS execution pro ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md index 4ffcb8dd5e..5cd3b7f298 100644 --- a/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-22-wsmprovhost_lolbas_execution_process_spawn.md @@ -53,7 +53,7 @@ The following analytic identifies `Wsmprovhost.exe` spawning a LOLBAS execution ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md b/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md index a84578c9cb..e953768ec6 100644 --- a/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md +++ b/docs/_posts/2021-11-23-mmc_lolbas_execution_process_spawn.md @@ -53,7 +53,7 @@ The following analytic identifies `mmc.exe` spawning a LOLBAS execution process. ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement diff --git a/docs/_posts/2021-11-30-attempt_to_delete_services.md b/docs/_posts/2021-11-24-attempt_to_delete_services.md similarity index 84% rename from docs/_posts/2021-11-30-attempt_to_delete_services.md rename to docs/_posts/2021-11-24-attempt_to_delete_services.md index ff3998ceee..475b5429c4 100644 --- a/docs/_posts/2021-11-30-attempt_to_delete_services.md +++ b/docs/_posts/2021-11-24-attempt_to_delete_services.md @@ -1,14 +1,20 @@ --- title: "Attempt To Delete Services" -excerpt: "Service Stop" +excerpt: "Service Stop, Create or Modify System Process, Windows Service" categories: - Endpoint -last_modified_at: 2021-11-30 +last_modified_at: 2021-11-24 toc: true toc_label: "" tags: - Service Stop - Impact + - Create or Modify System Process + - Persistence + - Privilege Escalation + - Windows Service + - Persistence + - Privilege Escalation - Splunk Behavioral Analytics - Endpoint_Processes --- @@ -24,7 +30,7 @@ The following analytic identifies Windows Service Control, `sc.exe`, attempting - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 +- **Last Updated**: 2021-11-24 - **Author**: Teoderick Contreras, splunk - **ID**: a0c8c292-d01a-11eb-aa18-acde48001122 @@ -35,6 +41,10 @@ The following analytic identifies Windows Service Control, `sc.exe`, attempting | ----------- | ----------- |--------------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | +| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + +| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | + #### Search ``` @@ -52,7 +62,7 @@ The following analytic identifies Windows Service Control, `sc.exe`, attempting #### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. #### Required field * _time @@ -85,6 +95,7 @@ It is possible administrative scripts may start/stop/delete services. Filter as #### Reference * [https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/](https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/) +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md) diff --git a/docs/_posts/2021-11-30-attempt_to_disable_services.md b/docs/_posts/2021-11-24-attempt_to_disable_services.md similarity index 96% rename from docs/_posts/2021-11-30-attempt_to_disable_services.md rename to docs/_posts/2021-11-24-attempt_to_disable_services.md index d6ea7f6082..cf953425b9 100644 --- a/docs/_posts/2021-11-30-attempt_to_disable_services.md +++ b/docs/_posts/2021-11-24-attempt_to_disable_services.md @@ -3,7 +3,7 @@ title: "Attempt To Disable Services" excerpt: "Service Stop" categories: - Endpoint -last_modified_at: 2021-11-30 +last_modified_at: 2021-11-24 toc: true toc_label: "" tags: @@ -24,7 +24,7 @@ The following analytic identifies Windows Service Control, `sc.exe`, attempting - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-11-30 +- **Last Updated**: 2021-11-24 - **Author**: Teoderick Contreras, Splunk - **ID**: afb31de4-d023-11eb-98d5-acde48001122 @@ -53,7 +53,7 @@ The following analytic identifies Windows Service Control, `sc.exe`, attempting #### How To Implement -To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed sc.exe may be used. +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. #### Required field * _time diff --git a/docs/_posts/2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md b/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md similarity index 72% rename from docs/_posts/2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md rename to docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md index 13ac7807ab..6b6f3289cc 100644 --- a/docs/_posts/2020-6-04-attempted_credential_dump_from_registry_via_reg_exe.md +++ b/docs/_posts/2021-11-29-attempted_credential_dump_from_registry_via_reg_exe.md @@ -1,14 +1,16 @@ --- title: "Attempted Credential Dump From Registry via Reg exe" -excerpt: "OS Credential Dumping" +excerpt: "OS Credential Dumping, Security Account Manager" categories: - Endpoint -last_modified_at: 2020-6-04 +last_modified_at: 2021-11-29 toc: true toc_label: "" tags: - OS Credential Dumping - Credential Access + - Security Account Manager + - Credential Access - Splunk Behavioral Analytics - Endpoint_Processes --- @@ -19,12 +21,12 @@ tags: #### Description -Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. +The following analytic identifies the use of `reg.exe` attempting to export Windows registry keys that contain hashed credentials. Adversaries will utilize this technique to capture and perform offline password cracking. - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-6-04 +- **Last Updated**: 2021-11-29 - **Author**: Jose Hernandez, Splunk - **ID**: 14038953-e5f2-4daf-acff-5452062baf03 @@ -35,6 +37,8 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th | ----------- | ----------- |--------------- | | [T1003](https://attack.mitre.org/techniques/T1003/) | OS Credential Dumping | Credential Access | +| [T1003.002](https://attack.mitre.org/techniques/T1003/002/) | Security Account Manager | Credential Access | + #### Search ``` @@ -53,7 +57,7 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th #### How To Implement -You must be ingesting windows endpoint data that tracks process activity, including parent-child relationships from your endpoints. +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. #### Required field * process_name @@ -61,6 +65,7 @@ You must be ingesting windows endpoint data that tracks process activity, includ * dest_device_id * dest_user_id * process +* cmd_line #### Kill Chain Phase @@ -75,7 +80,7 @@ None identified. | Risk Score | Impact | Confidence | Message | | ----------- | ----------- |--------------|--------------| -| 63.0 | 70 | 90 | Malicious actor is dumping stored credentials from the registry sections SAM, Security, or System. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | +| 63.0 | 70 | 90 | An attempt to save registry keys storing credentials has been performed on $dest_device_id$ by $dest_user_id$ via process $process_name$. | @@ -83,6 +88,7 @@ None identified. #### Reference * [https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml](https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml) +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets) @@ -93,4 +99,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-14-deny_permission_using_cacls_utility.md b/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md similarity index 89% rename from docs/_posts/2021-06-14-deny_permission_using_cacls_utility.md rename to docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md index e5bcfaa68b..ea6ac693df 100644 --- a/docs/_posts/2021-06-14-deny_permission_using_cacls_utility.md +++ b/docs/_posts/2021-11-29-deny_permission_using_cacls_utility.md @@ -3,7 +3,7 @@ title: "Deny Permission using Cacls Utility" excerpt: "File and Directory Permissions Modification" categories: - Endpoint -last_modified_at: 2021-06-14 +last_modified_at: 2021-11-29 toc: true toc_label: "" tags: @@ -19,12 +19,12 @@ tags: #### Description -This analytic identifies a potential adversary that changes the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft, ransomware or coinminer scripts. This behavior is meant to evade detection and prevent access to their component files. +The following analytic identifies the use of `cacls.exe`, `icacls.exe` or `xcacls.exe` placing the deny permission on a file or directory. Adversaries perform this behavior to prevent responders from reviewing or gaining access to adversary files on disk. - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-06-14 +- **Last Updated**: 2021-11-29 - **Author**: Teoderick Contreras, Splunk - **ID**: b76eae28-cd25-11eb-9c92-acde48001122 @@ -61,6 +61,7 @@ To successfully implement this search, you need to be ingesting logs with the pr * process_path * dest_user_id * process +* cmd_line #### Kill Chain Phase @@ -68,7 +69,7 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Known False Positives -network administrator may use this windows utility but this is not a common practice. +System administrators may use cacls utilities but this is not a common practice. Filter as needed. #### RBA @@ -94,4 +95,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/deny_permission_using_cacls_utility.yml) \| *version*: **2** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/deny_permission_using_cacls_utility.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md b/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md similarity index 70% rename from docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md rename to docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md index 76a31f1aa5..cb83d13749 100644 --- a/docs/_posts/2020-09-15-detect_dump_lsass_memory_using_comsvcs.md +++ b/docs/_posts/2021-11-29-detect_dump_lsass_memory_using_comsvcs.md @@ -3,7 +3,7 @@ title: "Detect Dump LSASS Memory using comsvcs" excerpt: "NTDS, OS Credential Dumping" categories: - Endpoint -last_modified_at: 2020-09-15 +last_modified_at: 2021-11-29 toc: true toc_label: "" tags: @@ -21,12 +21,12 @@ tags: #### Description -This search detects the memory of lsass.exe being dumped for offline credential theft attack. +The following analytic identifies credential dumping using comsvcs.dll with `regsvr32.exe`. This technique is common with adversaries who would like to dump the memory of lsass.exe and perform offline password cracking. - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2020-09-15 +- **Last Updated**: 2021-11-29 - **Author**: Jose Hernandez, Splunk - **ID**: 76bb9e35-f314-4c3d-a385-83c72a13ce4e @@ -44,11 +44,9 @@ This search detects the memory of lsass.exe being dumped for offline credential ``` | from read_ssa_enriched_events() -| where "Endpoint_Processes" IN(_datamodels) -| eval dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| eval tenant=ucast(map_get(input_event, "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name LIKE "%rundll32.exe%" AND match_regex(process, /(?i)comsvcs.dll[,\s]+MiniDump/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id) -| eval body=create_map(["event_id", event_id, "process_name", process_name, "process", process]) +| eval start_time = timestamp, end_time = timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, "process_name", process_name, "process", process]) | into write_ssa_detected_events(); ``` @@ -72,14 +70,14 @@ You must be ingesting endpoint data that tracks process activity, including Wind #### Known False Positives -None identified. +False positives should be limited, filter as needed. #### RBA | Risk Score | Impact | Confidence | Message | | ----------- | ----------- |--------------|--------------| -| 70.0 | 70 | 100 | Malicious actor is dumping encoded credentials via Microsoft's native comsvc DLL. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ | +| 70.0 | 70 | 100 | A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ by user $dest_device_user$. | @@ -87,6 +85,7 @@ None identified. #### Reference * [https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf](https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf) +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll) diff --git a/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md b/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md new file mode 100644 index 0000000000..d3151bc6e0 --- /dev/null +++ b/docs/_posts/2021-11-29-possible_lateral_movement_powershell_spawn.md @@ -0,0 +1,137 @@ +--- +title: "Possible Lateral Movement PowerShell Spawn" +excerpt: "Remote Services, Distributed Component Object Model, Windows Remote Management, Windows Management Instrumentation, Scheduled Task, Windows Service, PowerShell" +categories: + - Endpoint +last_modified_at: 2021-11-29 +toc: true +toc_label: "" +tags: + - Remote Services + - Lateral Movement + - Distributed Component Object Model + - Lateral Movement + - Windows Remote Management + - Lateral Movement + - Windows Management Instrumentation + - Execution + - Scheduled Task + - Execution + - Persistence + - Privilege Escalation + - Windows Service + - Persistence + - Privilege Escalation + - PowerShell + - Execution + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic assists with identifying a PowerShell process spawned as a child or grand child process of commonly abused processes during lateral movement techniques including `services.exe`, `wmiprsve.exe`, `svchost.exe`, `wsmprovhost.exe` and `mmc.exe`. Legitimate Windows features such as the Service Control Manager, Windows Management Instrumentation, Task Scheduler, Windows Remote Management and the DCOM protocol can be abused to start a process on a remote endpoint. Looking for PowerShell spawned out of this processes may reveal a lateral movement attack. Red Teams and adversaries alike may abuse these services during a breach for lateral movement and remote code execution. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-11-29 +- **Author**: Mauricio Velazco, Splunk +- **ID**: cb909b3e-512b-11ec-aa31-3e22fbd008af + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1021](https://attack.mitre.org/techniques/T1021/) | Remote Services | Lateral Movement | + +| [T1021.003](https://attack.mitre.org/techniques/T1021/003/) | Distributed Component Object Model | Lateral Movement | + +| [T1021.006](https://attack.mitre.org/techniques/T1021/006/) | Windows Remote Management | Lateral Movement | + +| [T1047](https://attack.mitre.org/techniques/T1047/) | Windows Management Instrumentation | Execution | + +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | + +| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | + +| [T1059.001](https://attack.mitre.org/techniques/T1059/001/) | PowerShell | Execution | + +#### Search + +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=wmiprvse.exe OR Processes.parent_process_name=services.exe OR Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wsmprovhost.exe OR Processes.parent_process_name=mmc.exe) (Processes.process_name=powershell.exe OR (Processes.process_name=cmd.exe AND Processes.process=*powershell.exe*) OR Processes.process_name=pwsh.exe OR (Processes.process_name=cmd.exe AND Processes.process=*pwsh.exe*)) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `possible_lateral_movement_powershell_spawn_filter` +``` + +#### Associated Analytic Story +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) +* [Malicious PowerShell](/stories/malicious_powershell) + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. + +#### Required field +* _time +* Processes.dest +* Processes.user +* Processes.parent_process_name +* Processes.parent_process +* Processes.original_file_name +* Processes.process_name +* Processes.process +* Processes.process_id +* Processes.parent_process_path +* Processes.process_path +* Processes.parent_process_id + + +#### Kill Chain Phase +* Lateral Movement +* Malicious PowerShell + + +#### Known False Positives +Legitimate applications may spawn PowerShell as a child process of the the identified processes. Filter as needed. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 45.0 | 90 | 50 | A PowerShell process was spawned as a child process of typically abused processes on $dest$ | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1021/003](https://attack.mitre.org/techniques/T1021/003) +* [https://attack.mitre.org/techniques/T1021/006/](https://attack.mitre.org/techniques/T1021/006/) +* [https://attack.mitre.org/techniques/T1047/](https://attack.mitre.org/techniques/T1047/) +* [https://attack.mitre.org/techniques/T1053.005/](https://attack.mitre.org/techniques/T1053.005/) +* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_powershell/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_powershell/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/possible_lateral_movement_powershell_spawn.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md new file mode 100644 index 0000000000..220322b755 --- /dev/null +++ b/docs/_posts/2021-11-29-randomly_generated_scheduled_task_name.md @@ -0,0 +1,110 @@ +--- +title: "Randomly Generated Scheduled Task Name" +excerpt: "Scheduled Task/Job, Scheduled Task" +categories: + - Endpoint +last_modified_at: 2021-11-29 +toc: true +toc_label: "" +tags: + - Scheduled Task/Job + - Execution + - Persistence + - Privilege Escalation + - Scheduled Task + - Execution + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate or build datasets for it, use at your own risk! + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following hunting analytic leverages Event ID 4698, `A scheduled task was created`, to identify the creation of a Scheduled Task with a suspicious, high entropy, Task Name. To achieve this, this analytic also leverages the `ut_shannon` function from the URL ToolBox Splunk application. Red teams and adversaries alike may abuse the Task Scheduler to create and start a remote Scheduled Task and obtain remote code execution. To achieve this goal, tools like Impacket or Crapmapexec, typically create a Scheduled Task with a random task name on the victim host. This hunting analytic may help defenders identify Scheduled Tasks created as part of a lateral movement attack. The entropy threshold `ut_shannon > 3` should be customized by users. The Command field can be used to determine if the task has malicious intent or not. + +- **Type**: Hunting +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-11-29 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 9d22a780-5165-11ec-ad4f-3e22fbd008af + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1053](https://attack.mitre.org/techniques/T1053/) | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | + +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | + +#### Search + +``` + `wineventlog_security` EventCode=4698 +| xmlkv Message +| lookup ut_shannon_lookup word as Task_Name +| where ut_shannon > 3 +| table _time, dest, Task_Name, ut_shannon, Command, Author, Enabled, Hidden +| `randomly_generated_scheduled_task_name_filter` +``` + +#### Associated Analytic Story +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) + + +#### How To Implement +To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA as well as the URL ToolBox application are also required. + +#### Required field +* _time +* dest +* Task_Name +* Description +* Command + + +#### Kill Chain Phase +* Privilege Escalation +* Lateral Movement +* Persistence + + +#### Known False Positives +Legitimate applications may use random Scheduled Task names. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 45.0 | 90 | 50 | A windows scheduled task with a suspicious task name was created on $dest$ | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) +* [https://splunkbase.splunk.com/app/2734/](https://splunkbase.splunk.com/app/2734/) +* [https://en.wikipedia.org/wiki/Entropy_(information_theory)](https://en.wikipedia.org/wiki/Entropy_(information_theory)) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/randomly_generated_scheduled_task_name.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md new file mode 100644 index 0000000000..5979cf17df --- /dev/null +++ b/docs/_posts/2021-11-29-randomly_generated_windows_service_name.md @@ -0,0 +1,106 @@ +--- +title: "Randomly Generated Windows Service Name" +excerpt: "Create or Modify System Process, Windows Service" +categories: + - Endpoint +last_modified_at: 2021-11-29 +toc: true +toc_label: "" +tags: + - Create or Modify System Process + - Persistence + - Privilege Escalation + - Windows Service + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate or build datasets for it, use at your own risk! + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following hunting analytic leverages Event ID 7045, `A new service was installed in the system`, to identify the installation of a Windows Service with a suspicious, high entropy, Service Name. To achieve this, this analytic also leverages the `ut_shannon` function from the URL ToolBox Splunk application. Red teams and adversaries alike may abuse the Service Control Manager to create and start a remote Windows Service and obtain remote code execution. To achieve this goal, some tools like Metasploit, Cobalt Strike and Impacket, typically create a Windows Service with a random service name on the victim host. This hunting analytic may help defenders identify Windows Services installed as part of a lateral movement attack. The entropy threshold `ut_shannon > 3` should be customized by users. The Service_File_Name field can be used to determine if the Windows Service has malicious intent or not. + +- **Type**: Hunting +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-11-29 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 2032a95a-5165-11ec-a2c3-3e22fbd008af + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1543](https://attack.mitre.org/techniques/T1543/) | Create or Modify System Process | Persistence, Privilege Escalation | + +| [T1543.003](https://attack.mitre.org/techniques/T1543/003/) | Windows Service | Persistence, Privilege Escalation | + +#### Search + +``` + `wineventlog_system` EventCode=7045 +| lookup ut_shannon_lookup word as Service_Name +| where ut_shannon > 3 +| table EventCode ComputerName Service_Name ut_shannon Service_Start_Type Service_Type Service_File_Name +| `randomly_generated_windows_service_name_filter` +``` + +#### Associated Analytic Story +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. The Windows TA as well as the URL ToolBox application are also required. + +#### Required field +* _time +* EventCode +* ComputerName +* Service_File_Name +* Service_Type +* Service_Name +* Service_Start_Type + + +#### Kill Chain Phase +* Privilege Escalation +* Lateral Movement + + +#### Known False Positives +Legitimate applications may use random Windows Service names. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 45.0 | 90 | 50 | A Windows Service with a suspicious service name was installed on $ComputerName$ | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1543/003/](https://attack.mitre.org/techniques/T1543/003/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/randomly_generated_windows_service_name.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-11-30-delete_a_net_user.md b/docs/_posts/2021-11-30-delete_a_net_user.md index a342b84c70..fb9fc83d25 100644 --- a/docs/_posts/2021-11-30-delete_a_net_user.md +++ b/docs/_posts/2021-11-30-delete_a_net_user.md @@ -41,7 +41,7 @@ This analytic will detect a suspicious net.exe/net1.exe command-line to delete a | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) -| where cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND like(cmd_line, "%user%") AND (process_name="net1.exe" OR process_name="net.exe") +| where cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" OR process_name="net.exe") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) | into write_ssa_detected_events(); ``` @@ -52,7 +52,7 @@ This analytic will detect a suspicious net.exe/net1.exe command-line to delete a #### How To Implement -o successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe may be used. +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe may be used. #### Required field * _time diff --git a/docs/_posts/2021-12-01-disable_net_user_account.md b/docs/_posts/2021-11-30-disable_net_user_account.md similarity index 92% rename from docs/_posts/2021-12-01-disable_net_user_account.md rename to docs/_posts/2021-11-30-disable_net_user_account.md index fdca976934..b2d4b530bb 100644 --- a/docs/_posts/2021-12-01-disable_net_user_account.md +++ b/docs/_posts/2021-11-30-disable_net_user_account.md @@ -1,14 +1,19 @@ --- title: "Disable Net User Account" -excerpt: "Service Stop" +excerpt: "Service Stop, Valid Accounts" categories: - Endpoint -last_modified_at: 2021-12-01 +last_modified_at: 2021-11-30 toc: true toc_label: "" tags: - Service Stop - Impact + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access - Splunk Behavioral Analytics - Endpoint_Processes --- @@ -24,7 +29,7 @@ This analytic will identify a suspicious command-line that disables a user accou - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-12-01 +- **Last Updated**: 2021-11-30 - **Author**: Teoderick Contreras, Splunk - **ID**: ba858b08-d26c-11eb-af9b-acde48001122 @@ -35,6 +40,8 @@ This analytic will identify a suspicious command-line that disables a user accou | ----------- | ----------- |--------------- | | [T1489](https://attack.mitre.org/techniques/T1489/) | Service Stop | Impact | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + #### Search ``` diff --git a/docs/_posts/2021-2-1-first_time_seen_command_line_argument.md b/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md similarity index 76% rename from docs/_posts/2021-2-1-first_time_seen_command_line_argument.md rename to docs/_posts/2021-11-30-first_time_seen_command_line_argument.md index 6084c9da04..c6aa349205 100644 --- a/docs/_posts/2021-2-1-first_time_seen_command_line_argument.md +++ b/docs/_posts/2021-11-30-first_time_seen_command_line_argument.md @@ -1,15 +1,14 @@ --- title: "First time seen command line argument" -excerpt: "Command and Scripting Interpreter, Regsvr32, Indirect Command Execution" +excerpt: "Command and Scripting Interpreter, Indirect Command Execution" categories: - Endpoint -last_modified_at: 2021-2-1 +last_modified_at: 2021-11-30 toc: true toc_label: "" tags: - Command and Scripting Interpreter - Execution - - Regsvr32 - Indirect Command Execution - Defense Evasion - Splunk Behavioral Analytics @@ -22,12 +21,12 @@ tags: #### Description -This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. This is an implementation on SPL2 of the rule `First time seen command line argument` by @bpatel. +This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. This is an implementation on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following analytic identifies first time seen command-line arguments on a single endpoint. The analytic looks for arguments instantiated by `cmd.exe /c` and the associated command-line. Adversaries automate or spawn multiple processes using this method, this analytic may assist with identifying the first time it's been found on this endpoint.' - **Type**: Anomaly - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-2-1 +- **Last Updated**: 2021-11-30 - **Author**: Ignacio Bermudez Corrales, Splunk - **ID**: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 @@ -38,8 +37,6 @@ This search looks for command-line arguments that use a `/c` parameter to execut | ----------- | ----------- |--------------- | | [T1059](https://attack.mitre.org/techniques/T1059/) | Command and Scripting Interpreter | Execution | -| [T1117](https://attack.mitre.org/techniques/T1117/) | Regsvr32 | | - | [T1202](https://attack.mitre.org/techniques/T1202/) | Indirect Command Execution | Defense Evasion | #### Search @@ -64,7 +61,7 @@ This search looks for command-line arguments that use a `/c` parameter to execut #### How To Implement -You must be populating the endpoint data model for SSA and specifically the process_name and the process fields +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. #### Required field * process_name @@ -72,6 +69,7 @@ You must be populating the endpoint data model for SSA and specifically the proc * dest_device_id * dest_user_id * process +* cmd_line #### Kill Chain Phase @@ -80,14 +78,14 @@ You must be populating the endpoint data model for SSA and specifically the proc #### Known False Positives -Legitimate programs can also use command-line arguments to execute. Please verify the command-line arguments to check what command/program is being executed. We recommend customizing the `first_time_seen_cmd_line_filter` macro to exclude legitimate parent_process_name +Legitimate programs use command-line arguments to execute. Verify the command-line arguments to check what command/program is being executed. Filtering will be needed. #### RBA | Risk Score | Impact | Confidence | Message | | ----------- | ----------- |--------------|--------------| -| 30.0 | 50 | 60 | A cmd process $process_name$ with commandline $cmd_line$ try to execute command has not previously seen in host $dest_device_id$ | +| 30.0 | 50 | 60 | A process $process_name$ ha been identified in the environment with a command-line $cmd_line$ not previously seen before on host $dest_device_id$ | @@ -102,4 +100,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/first_time_seen_command_line_argument.yml) \| *version*: **3** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/first_time_seen_command_line_argument.yml) \| *version*: **4** \ No newline at end of file diff --git a/docs/_posts/2021-06-14-grant_permission_using_cacls_utility.md b/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md similarity index 88% rename from docs/_posts/2021-06-14-grant_permission_using_cacls_utility.md rename to docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md index 835a164590..db17a43182 100644 --- a/docs/_posts/2021-06-14-grant_permission_using_cacls_utility.md +++ b/docs/_posts/2021-11-30-grant_permission_using_cacls_utility.md @@ -3,7 +3,7 @@ title: "Grant Permission Using Cacls Utility" excerpt: "File and Directory Permissions Modification" categories: - Endpoint -last_modified_at: 2021-06-14 +last_modified_at: 2021-11-30 toc: true toc_label: "" tags: @@ -19,12 +19,12 @@ tags: #### Description -This analytic identifies potential adversaries that modify the security permission of a specific file or directory. This technique is commonly seen in APT tradecraft, ransomware and coinminer scripts to evade detections and restrict access to their component files. +The following analytic identifies the use of `cacls.exe`, `icacls.exe` or `xcacls.exe` placing the grant permission on a file or directory. Adversaries perform this behavior to allow components of their files to run, however it allows responders to review or gaining access to adversary files on disk. - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-06-14 +- **Last Updated**: 2021-11-30 - **Author**: Teoderick Contreras, Splunk - **ID**: c6da561a-cd29-11eb-ae65-acde48001122 @@ -61,6 +61,7 @@ To successfully implement this search, you need to be ingesting logs with the pr * process_path * dest_user_id * process +* cmd_line #### Kill Chain Phase @@ -68,7 +69,7 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Known False Positives -network administrator may use this windows utility but this is not a common practice. +System administrators may use cacls utilities but this is not a common practice. Filter as needed. #### RBA @@ -94,4 +95,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/grant_permission_using_cacls_utility.yml) \| *version*: **2** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/grant_permission_using_cacls_utility.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-06-15-modify_acls_permission_of_files_or_folders.md b/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md similarity index 93% rename from docs/_posts/2021-06-15-modify_acls_permission_of_files_or_folders.md rename to docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md index b50d327eec..a3cbf9e808 100644 --- a/docs/_posts/2021-06-15-modify_acls_permission_of_files_or_folders.md +++ b/docs/_posts/2021-11-30-modify_acls_permission_of_files_or_folders.md @@ -3,7 +3,7 @@ title: "Modify ACLs Permission Of Files Or Folders" excerpt: "File and Directory Permissions Modification" categories: - Endpoint -last_modified_at: 2021-06-15 +last_modified_at: 2021-11-30 toc: true toc_label: "" tags: @@ -19,12 +19,12 @@ tags: #### Description -This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone or to a specific user. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. This behavior is a good indicator if this command seen on a machine utilized by an account with no permission to do so. +This analytic identifies suspicious modification of ACL permission to a files or folder to make it available to everyone or to a specific user. This technique may be used by the adversary to evade ACLs or protected files access. This changes is commonly configured by the file or directory owner with appropriate permission. This behavior raises suspicion if this command is seen on an endpoint utilized by an account with no permission to do so. - **Type**: Anomaly - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-06-15 +- **Last Updated**: 2021-11-30 - **Author**: Teoderick Contreras, Splunk - **ID**: 9ae9a48a-cdbe-11eb-875a-acde48001122 @@ -61,6 +61,7 @@ To successfully implement this search, you need to be ingesting logs with the pr * process_path * dest_user_id * process +* cmd_line #### Kill Chain Phase @@ -68,7 +69,7 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Known False Positives -network administrator may use this windows utility. filter is needed. +System administrators may use this windows utility. filter is needed. #### RBA @@ -94,4 +95,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/modify_acls_permission_of_files_or_folders.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/modify_acls_permission_of_files_or_folders.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_at_the_destination_device.md b/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md similarity index 85% rename from docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_at_the_destination_device.md rename to docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md index b3dbae4547..45c68cc56e 100644 --- a/docs/_posts/2021-11-05-potential_pass_the_token_or_hash_observed_at_the_destination_device.md +++ b/docs/_posts/2021-11-30-potential_pass_the_token_or_hash_observed_at_the_destination_device.md @@ -3,7 +3,7 @@ title: "Potential Pass the Token or Hash Observed at the Destination Device" excerpt: "Use Alternate Authentication Material, Pass the Hash" categories: - Endpoint -last_modified_at: 2021-11-05 +last_modified_at: 2021-11-30 toc: true toc_label: "" tags: @@ -23,12 +23,12 @@ tags: #### Description -This detection identifies potential Pass the Token or Pass the Hash credential exploits. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by a detination device. +This detection identifies potential Pass the Token or Pass the Hash credential stealing. We detect the main side effect of these attacks, which is a transition from the dominant Kerberos logins to rare NTLM logins for a given user, as reported by a detination device. - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication) -- **Last Updated**: 2021-11-05 +- **Last Updated**: 2021-11-30 - **Author**: Stanislav Miskovic, Splunk - **ID**: 82e76b80-5cdb-4899-9b43-85dbe777b36d @@ -47,7 +47,7 @@ This detection identifies potential Pass the Token or Pass the Hash credential e | from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") AND dest_user_id != null AND dest_device_id != null @@ -57,13 +57,13 @@ This detection identifies potential Pass the Token or Pass the Hash credential e | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) -| eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", endNTLMTime]) +| eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", endNTLMTime]) | into write_ssa_detected_events(); ``` #### Associated Analytic Story -* [Lateral Movement](/stories/lateral_movement) +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) #### How To Implement @@ -98,6 +98,7 @@ Environments in which NTLM is used extremely rarely and for benign purposes (suc #### Reference * [https://attack.mitre.org/techniques/T1550/002/](https://attack.mitre.org/techniques/T1550/002/) +* [https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/](https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/) @@ -108,4 +109,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device.yml) \| *version*: **2** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-05-20-rare_parent-child_process_relationship.md b/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md similarity index 89% rename from docs/_posts/2021-05-20-rare_parent-child_process_relationship.md rename to docs/_posts/2021-11-30-rare_parent-child_process_relationship.md index a45910e86f..5b01c4cab5 100644 --- a/docs/_posts/2021-05-20-rare_parent-child_process_relationship.md +++ b/docs/_posts/2021-11-30-rare_parent-child_process_relationship.md @@ -3,7 +3,7 @@ title: "Rare Parent-Child Process Relationship" excerpt: "Exploitation for Client Execution, Command and Scripting Interpreter, Scheduled Task/Job, Software Deployment Tools" categories: - Endpoint -last_modified_at: 2021-05-20 +last_modified_at: 2021-11-30 toc: true toc_label: "" tags: @@ -28,12 +28,12 @@ tags: #### Description -An attacker may use LOLBAS tools spawned from vulnerable applications not typically used by system administrators. This search leverages the Splunk Streaming ML DSP plugin to find rare parent/child relationships. The list of application has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries +An attacker may use LOLBAS tools spawned from vulnerable applications not typically used by system administrators. This analytic leverages the Splunk Streaming ML DSP plugin to find rare parent/child relationships. The list of application has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries - **Type**: Anomaly - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-05-20 +- **Last Updated**: 2021-11-30 - **Author**: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk - **ID**: cf090c78-bcc6-11eb-8529-0242ac130003 @@ -82,6 +82,7 @@ Collect endpoint data such as sysmon or 4688 events. * _time * dest_device_id * dest_user_id +* cmd_line #### Kill Chain Phase @@ -89,8 +90,7 @@ Collect endpoint data such as sysmon or 4688 events. #### Known False Positives -Some custom tools used by admins could be used rarely to launch remotely applications. This might trigger false positives at the beginning when it hasn't collected yet enough data to construct the baseline. - +Some custom tools used by administrators could be used rarely to launch remotely applications. This might trigger false positives at the beginning when it has not collected yet enough data to construct the baseline. @@ -98,6 +98,9 @@ Some custom tools used by admins could be used rarely to launch remotely applica #### Reference +* [https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries](https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries) + + #### Test Dataset Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). @@ -106,4 +109,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rare_parent-child_process_relationship.yml) \| *version*: **1** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/rare_parent-child_process_relationship.yml) \| *version*: **2** \ No newline at end of file diff --git a/docs/_posts/2021-06-21-resize_shadowstorage_volume.md b/docs/_posts/2021-11-30-resize_shadowstorage_volume.md similarity index 89% rename from docs/_posts/2021-06-21-resize_shadowstorage_volume.md rename to docs/_posts/2021-11-30-resize_shadowstorage_volume.md index abce666679..486182f221 100644 --- a/docs/_posts/2021-06-21-resize_shadowstorage_volume.md +++ b/docs/_posts/2021-11-30-resize_shadowstorage_volume.md @@ -3,7 +3,7 @@ title: "Resize Shadowstorage Volume" excerpt: "Service Stop" categories: - Endpoint -last_modified_at: 2021-06-21 +last_modified_at: 2021-11-30 toc: true toc_label: "" tags: @@ -19,12 +19,12 @@ tags: #### Description -The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible +The following analytic identifies the resizing of shadowstorage using vssadmin.exe to avoid the shadow volumes being made again. This technique is typically found used by adversaries during a ransomware event and a precursor to deleting the shadowstorage. - **Type**: TTP - **Product**: Splunk Behavioral Analytics - **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) -- **Last Updated**: 2021-06-21 +- **Last Updated**: 2021-11-30 - **Author**: Teoderick Contreras, Splunk - **ID**: dbc30554-d27e-11eb-9e5e-acde48001122 @@ -97,4 +97,4 @@ Alternatively you can replay a dataset into a [Splunk Attack Range](https://gith -[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/resize_shadowstorage_volume.yml) \| *version*: **2** \ No newline at end of file +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/resize_shadowstorage_volume.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md new file mode 100644 index 0000000000..e5ad7cad7b --- /dev/null +++ b/docs/_posts/2021-12-01-unusual_number_of_computer_service_tickets_requested.md @@ -0,0 +1,107 @@ +--- +title: "Unusual Number of Computer Service Tickets Requested" +excerpt: "Valid Accounts" +categories: + - Endpoint +last_modified_at: 2021-12-01 +toc: true +toc_label: "" +tags: + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate or build datasets for it, use at your own risk! + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following hunting analytic leverages Event ID 4769, `A Kerberos service ticket was requested`, to identify an unusual number of computer service ticket requests from one source. When a domain joined endpoint connects to a remote endpoint, it first will request a Kerberos Ticket with the computer name as the Service Name. An endpoint requesting a large number of computer service tickets for different endpoints could represent malicious behavior like lateral movement, malware staging, reconnaissance, etc.\ +The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual number of service requests. To customize this analytic, users can try different combinations of the `bucket` span time, the calculation of the `upperBound` field as well as the Outlier calculation. This logic can be used for real time security monitoring as well as threat hunting exercises.\ + +- **Type**: Hunting +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-12-01 +- **Author**: Mauricio Velazco, Splunk +- **ID**: ac3b81c0-52f4-11ec-ac44-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +#### Search + +``` + `wineventlog_security` EventCode=4769 Service_Name="*$" Account_Name!="*$*" +| bucket span=2m _time +| stats dc(Service_Name) AS unique_targets values(Service_Name) as host_targets by _time, Client_Address, Account_Name +| eventstats avg(unique_targets) as comp_avg , stdev(unique_targets) as comp_std by Client_Address, Account_Name +| eval upperBound=(comp_avg+comp_std*3) +| eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) +| `unusual_number_of_computer_service_tickets_requested_filter` +``` + +#### Associated Analytic Story +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) + + +#### How To Implement +To successfully implement this search, you need to be ingesting Domain Controller and Kerberos events. The Advanced Security Audit policy setting `Audit Kerberos Authentication Service` within `Account Logon` needs to be enabled. + +#### Required field +* _time +* EventCode +* Ticket_Options +* Ticket_Encryption_Type +* dest +* service +* service_id + + +#### Kill Chain Phase +* Reconnaissance +* Exploitation +* Lateral Movement + + +#### Known False Positives +An single endpoint requesting a large number of computer service tickets is not common behavior. Possible false positive scenarios include but are not limited to vulnerability scanners, administration systeams and missconfigured systems. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 42.0 | 70 | 60 | None | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1078/](https://attack.mitre.org/techniques/T1078/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/unusual_number_of_computer_service_tickets_requested.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md new file mode 100644 index 0000000000..68d8b11af7 --- /dev/null +++ b/docs/_posts/2021-12-01-unusual_number_of_remote_endpoint_authentication_events.md @@ -0,0 +1,106 @@ +--- +title: "Unusual Number of Remote Endpoint Authentication Events" +excerpt: "Valid Accounts" +categories: + - Endpoint +last_modified_at: 2021-12-01 +toc: true +toc_label: "" +tags: + - Valid Accounts + - Defense Evasion + - Persistence + - Privilege Escalation + - Initial Access + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Endpoint +--- + +### ⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION +We have not been able to test, simulate or build datasets for it, use at your own risk! + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following hunting analytic leverages Event ID 4624, `An account was successfully logged on`, to identify an unusual number of remote authentication attempts coming from one source. An endpoint authenticating to a large number of remote endpoints could represent malicious behavior like lateral movement, malware staging, reconnaissance, etc.\ +The detection calculates the standard deviation for each host and leverages the 3-sigma statistical rule to identify an unusual high number of authentication events. To customize this analytic, users can try different combinations of the `bucket` span time, the calculation of the `upperBound` field as well as the Outlier calculation. This logic can be used for real time security monitoring as well as threat hunting exercises.\ + +- **Type**: Hunting +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Last Updated**: 2021-12-01 +- **Author**: Mauricio Velazco, Splunk +- **ID**: acb5dc74-5324-11ec-a36d-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1078](https://attack.mitre.org/techniques/T1078/) | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access | + +#### Search + +``` + `wineventlog_security` EventCode=4624 Logon_Type=3 Account_Name!="*$" +| eval Source_Account = mvindex(Account_Name, 1) +| bucket span=2m _time +| stats dc(ComputerName) AS unique_targets values(ComputerName) as target_hosts by _time, Source_Network_Address, Source_Account +| eventstats avg(unique_targets) as comp_avg , stdev(unique_targets) as comp_std by Source_Network_Address, Source_Account +| eval upperBound=(comp_avg+comp_std*3) +| eval isOutlier=if(unique_targets >10 and unique_targets >= upperBound, 1, 0) `unusual_number_of_remote_endpoint_authentication_events_filter` +``` + +#### Associated Analytic Story +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) + + +#### How To Implement +To successfully implement this search, you need to be ingesting Windows Event Logs from domain controllers aas well as member servers and workstations. The Advanced Security Audit policy setting `Audit Logon` within `Logon/Logoff` needs to be enabled. + +#### Required field +* _time +* EventCode +* Logon_Type +* Caller_Process_Name +* Security_ID +* Account_Name +* ComputerName + + +#### Kill Chain Phase +* Reconnaissance +* Lateral Movement + + +#### Known False Positives +An single endpoint authenticating to a large number of hosts is not common behavior. Possible false positive scenarios include but are not limited to vulnerability scanners, jump servers and missconfigured systems. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 42.0 | 70 | 60 | None | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1078/](https://attack.mitre.org/techniques/T1078/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/experimental/endpoint/unusual_number_of_remote_endpoint_authentication_events.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md b/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md new file mode 100644 index 0000000000..ebd83b1027 --- /dev/null +++ b/docs/_posts/2021-12-03-detect_rclone_command-line_usage.md @@ -0,0 +1,104 @@ +--- +title: "Detect RClone Command-Line Usage" +excerpt: "Automated Exfiltration" +categories: + - Endpoint +last_modified_at: 2021-12-03 +toc: true +toc_label: "" +tags: + - Automated Exfiltration + - Exfiltration + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This analytic identifies commonly used command-line arguments used by `rclone.exe` to initiate a file transfer. Some arguments were negated as they are specific to the configuration used by adversaries. In particular, an adversary may list the files or directories of the remote file share using `ls` or `lsd`, which is not indicative of malicious behavior. During triage, at this stage of a ransomware event, exfiltration is about to occur or has already. Isolate the endpoint and continue investigating by review file modifications and parallel processes. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-03 +- **Author**: Michael Haag, Splunk +- **ID**: e8b74268-5454-11ec-a799-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1020](https://attack.mitre.org/techniques/T1020/) | Automated Exfiltration | Exfiltration | + +#### Search + +``` + +| from read_ssa_enriched_events() +| where "Endpoint_Processes" IN(_datamodels) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="rclone.exe" AND (like (cmd_line, "%copy%") OR like (cmd_line, "%mega%")OR like (cmd_line, "%pcloud%") OR like (cmd_line, "%ftp%") OR like (cmd_line, "%--config%") OR like (cmd_line, "%--progress%") OR like (cmd_line, "%--no-check-certificate%") OR like (cmd_line, "%--ignore-existing%") OR like (cmd_line, "%--auto-confirm%") OR like (cmd_line, "%--transfers%") OR like (cmd_line, "%--multi-thread-streams%")) +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) +| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [DarkSide Ransomware](/stories/darkside_ransomware) +* [Ransomware](/stories/ransomware) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. + +#### Required field +* _time +* dest_device_id +* process_name +* parent_process_name +* process_path +* dest_user_id +* process +* cmd_line + + +#### Kill Chain Phase +* Exfiltration + + +#### Known False Positives +False positives should be limited as this is restricted to the Rclone process name. Filter or tune the analytic as needed. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 35.0 | 50 | 70 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a remote cloud service to move files or folders. | + + + + +#### Reference + +* [https://redcanary.com/blog/rclone-mega-extortion/](https://redcanary.com/blog/rclone-mega-extortion/) +* [https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html](https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html) +* [https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/](https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/) +* [https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/](https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/detect_rclone_command-line_usage.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-03-short_lived_scheduled_task.md b/docs/_posts/2021-12-03-short_lived_scheduled_task.md new file mode 100644 index 0000000000..63f17f0416 --- /dev/null +++ b/docs/_posts/2021-12-03-short_lived_scheduled_task.md @@ -0,0 +1,102 @@ +--- +title: "Short Lived Scheduled Task" +excerpt: "Scheduled Task" +categories: + - Endpoint +last_modified_at: 2021-12-03 +toc: true +toc_label: "" +tags: + - Scheduled Task + - Execution + - Persistence + - Privilege Escalation + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic leverages Windows Security EventCode 4698, `A scheduled task was created` and Windows Security EventCode 4699, `A scheduled task was deleted` to identify scheduled tasks created and deleted in less than 30 seconds. This behavior may represent a lateral movement attack abusing the Task Scheduler to obtain code execution. Red Teams and adversaries alike may abuse the Task Scheduler for lateral movement and remote code execution. + +- **Type**: TTP +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **Last Updated**: 2021-12-03 +- **Author**: Mauricio Velazco, Splunk +- **ID**: 6fa31414-546e-11ec-adfa-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1053.005](https://attack.mitre.org/techniques/T1053/005/) | Scheduled Task | Execution, Persistence, Privilege Escalation | + +#### Search + +``` + `wineventlog_security` EventCode=4698 OR EventCode=4699 +| xmlkv Message +| transaction Task_Name startswith=(EventCode=4698) endswith=(EventCode=4699) +| eval short_lived=case((duration<30),"TRUE") +| search short_lived = TRUE +| table _time, ComputerName, Account_Name, Command, Task_Name, short_lived +| `short_lived_scheduled_task_filter` +``` + +#### Associated Analytic Story +* [Active Directory Lateral Movement](/stories/active_directory_lateral_movement) + + +#### How To Implement +To successfully implement this search, you need to be ingesting Windows Security Event Logs with 4698 EventCode enabled. The Windows TA is also required. + +#### Required field +* _time +* dest +* ComputerName +* Account_Name +* Task_Name +* Description +* Command + + +#### Kill Chain Phase +* Lateral Movement + + +#### Known False Positives +Although uncommon, legitimate applications may create and delete a Scheduled Task within 30 seconds. Filter as needed. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 81.0 | 90 | 90 | A windows scheduled task was created and deleted in 30 seconds on $ComputerName$ | + + + + +#### Reference + +* [https://attack.mitre.org/techniques/T1053/005/](https://attack.mitre.org/techniques/T1053/005/) +* [https://docs.microsoft.com/en-us/windows/win32/taskschd/about-the-task-scheduler](https://docs.microsoft.com/en-us/windows/win32/taskschd/about-the-task-scheduler) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-security.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/lateral_movement/windows-security.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/short_lived_scheduled_task.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md b/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md new file mode 100644 index 0000000000..38035003f0 --- /dev/null +++ b/docs/_posts/2021-12-03-windows_curl_upload_to_remote_destination.md @@ -0,0 +1,108 @@ +--- +title: "Windows Curl Upload to Remote Destination" +excerpt: "Ingress Tool Transfer" +categories: + - Endpoint +last_modified_at: 2021-12-03 +toc: true +toc_label: "" +tags: + - Ingress Tool Transfer + - Command And Control + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +The following analytic identifies the use of Windows Curl.exe uploading a file to a remote destination. \ +`-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. \ +`-d` or `--data` POST is the HTTP method that was invented to send data to a receiving web application, and it is, for example, how most common HTML forms on the web work. \ +HTTP multipart formposts are done with `-F`, but this appears to not be compatible with the Windows version of Curl. Will update if identified adversary tradecraft. \ +Adversaries may use one of the three methods based on the remote destination and what they are attempting to upload (zip vs txt). During triage, review parallel processes for further behavior. In addition, identify if the upload was successful in network logs. If a file was uploaded, isolate the endpoint and review. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-03 +- **Author**: Michael Haag, Splunk +- **ID**: cc8d046a-543b-11ec-b864-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1105](https://attack.mitre.org/techniques/T1105/) | Ingress Tool Transfer | Command And Control | + +#### Search + +``` + +| from read_ssa_enriched_events() +| where "Endpoint_Processes" IN(_datamodels) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + +| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="curl.exe" AND (like (cmd_line, "%-T %") OR like (cmd_line, "%--upload-file %")OR like (cmd_line, "%-d %") OR like (cmd_line, "%--data %") OR like (cmd_line, "%-F %")) + +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) +| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Ingress Tool Transfer](/stories/ingress_tool_transfer) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. + +#### Required field +* _time +* dest_device_id +* process_name +* parent_process_name +* process_path +* dest_user_id +* process +* cmd_line + + +#### Kill Chain Phase +* Exfiltration + + +#### Known False Positives +False positives may be limited to source control applications and may be required to be filtered out. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 80 | 100 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote destination. | + + + + +#### Reference + +* [https://everything.curl.dev/usingcurl/uploads](https://everything.curl.dev/usingcurl/uploads) +* [https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409](https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409) +* [https://twitter.com/d1r4c/status/1279042657508081664?s=20](https://twitter.com/d1r4c/status/1279042657508081664?s=20) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon_curl_upload.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/windows_curl_upload_to_remote_destination.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md b/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md new file mode 100644 index 0000000000..cfca2f917e --- /dev/null +++ b/docs/_posts/2021-12-07-bcdedit_failure_recovery_modification.md @@ -0,0 +1,99 @@ +--- +title: "BCDEdit Failure Recovery Modification" +excerpt: "Inhibit System Recovery" +categories: + - Endpoint +last_modified_at: 2021-12-07 +toc: true +toc_label: "" +tags: + - Inhibit System Recovery + - Impact + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This search looks for flags passed to bcdedit.exe modifications to the built-in Windows error recovery boot configurations. This is typically used by ransomware to prevent recovery. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-07 +- **Author**: Michael Haag, Splunk +- **ID**: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | + +#### Search + +``` + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bcdedit.exe" AND (like (cmd_line, "%recoveryenabled%") AND like (cmd_line, "%no%")) +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Ryuk Ransomware](/stories/ryuk_ransomware) +* [Ransomware](/stories/ransomware) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. + +#### Required field +* _time +* dest_device_id +* process_name +* parent_process_name +* process_path +* dest_user_id +* process +* cmd_line + + +#### Kill Chain Phase +* Actions on Objectives + + +#### Known False Positives +Administrators may modify the boot configuration. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 80.0 | 100 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability to recover the endpoint. | + + + + +#### Reference + +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/bcdedit_failure_recovery_modification.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md b/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md new file mode 100644 index 0000000000..98a2b60fac --- /dev/null +++ b/docs/_posts/2021-12-07-dns_exfiltration_using_nslookup_app.md @@ -0,0 +1,105 @@ +--- +title: "DNS Exfiltration Using Nslookup App" +excerpt: "Exfiltration Over Alternative Protocol" +categories: + - Endpoint +last_modified_at: 2021-12-07 +toc: true +toc_label: "" +tags: + - Exfiltration Over Alternative Protocol + - Exfiltration + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This search is to detect potential DNS exfiltration using nslookup application. This technique are seen in couple of malware and APT group to exfiltrated collected data in a infected machine or infected network. This detection is looking for unique use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are commonly used by attacker and also the retry parameter which is designed to query C2 DNS multiple tries. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-07 +- **Author**: Michael Haag, Splunk +- **ID**: 2452e632-9e0d-11eb-34ba-acde48001122 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1048](https://attack.mitre.org/techniques/T1048/) | Exfiltration Over Alternative Protocol | Exfiltration | + +#### Search + +``` + +| from read_ssa_enriched_events() +| where "Endpoint_Processes" IN(_datamodels) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="nslookup.exe" AND (like (cmd_line, "%-querytype=%") OR like (cmd_line, "%-qt=%") OR like (cmd_line, "%-q=%") OR like (cmd_line, "%-type=%") OR like (cmd_line, "%-retry=%")) +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) +| eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Suspicious DNS Traffic](/stories/suspicious_dns_traffic) +* [Dynamic DNS](/stories/dynamic_dns) +* [Command and Control](/stories/command_and_control) +* [Data Exfiltration](/stories/data_exfiltration) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. + +#### Required field +* _time +* dest_device_id +* process_name +* parent_process_name +* process_path +* dest_user_id +* process +* cmd_line + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +It is possible for some legitimate administrative utilities to use similar cmd_line parameters. Filter as needed. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 72.0 | 90 | 80 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related to DNS exfiltration. | + + + + +#### Reference + +* [https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html](https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html) +* [https://www.varonis.com/blog/dns-tunneling/](https://www.varonis.com/blog/dns-tunneling/) +* [https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/](https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + +* [https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log](https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/dns_exfiltration_using_nslookup_app.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-fsutil_zeroing_file.md b/docs/_posts/2021-12-07-fsutil_zeroing_file.md new file mode 100644 index 0000000000..c0205bfdcb --- /dev/null +++ b/docs/_posts/2021-12-07-fsutil_zeroing_file.md @@ -0,0 +1,98 @@ +--- +title: "Fsutil Zeroing File" +excerpt: "Indicator Removal on Host" +categories: + - Endpoint +last_modified_at: 2021-12-07 +toc: true +toc_label: "" +tags: + - Indicator Removal on Host + - Defense Evasion + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This search is to detect a suspicious fsutil process to zeroing a target file. This technique was seen in lockbit ransomware where it tries to zero out its malware path as part of its defense evasion after encrypting the compromised host. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-07 +- **Author**: Michael Haag, Splunk +- **ID**: f792cdc9-43ee-4429-a3c0-ffce4fed1a85 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1070](https://attack.mitre.org/techniques/T1070/) | Indicator Removal on Host | Defense Evasion | + +#### Search + +``` + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" AND (like (cmd_line, "%setzerodata%")) +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Ransomware](/stories/ransomware) + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. Tune and filter known instances where renamed net.exe may be used. + +#### Required field +* _time +* dest_device_id +* process_name +* parent_process_name +* process_path +* dest_user_id +* process +* cmd_line + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +System administrators or scripts may delete user accounts via this technique. Filter as needed. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 54.0 | 60 | 90 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file deletion. | + + + + +#### Reference + +* [https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/](https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/) +* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/fsutil_zeroing_file.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md b/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md new file mode 100644 index 0000000000..a1fa6e4f40 --- /dev/null +++ b/docs/_posts/2021-12-07-wbadmin_delete_system_backups.md @@ -0,0 +1,101 @@ +--- +title: "WBAdmin Delete System Backups" +excerpt: "Inhibit System Recovery" +categories: + - Endpoint +last_modified_at: 2021-12-07 +toc: true +toc_label: "" +tags: + - Inhibit System Recovery + - Impact + - Splunk Behavioral Analytics + - Endpoint_Processes +--- + + + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +This search looks for flags passed to wbadmin.exe (Windows Backup Administrator Tool) that delete backup files. This is typically used by ransomware to prevent recovery. + +- **Type**: TTP +- **Product**: Splunk Behavioral Analytics +- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Last Updated**: 2021-12-07 +- **Author**: Michael Haag, Splunk +- **ID**: 71efbf52-4dbb-4c00-a520-306aa546cbb7 + + +#### [ATT&CK](https://attack.mitre.org/) + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------- | +| [T1490](https://attack.mitre.org/techniques/T1490/) | Inhibit System Recovery | Impact | + +#### Search + +``` + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) +| where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, "%systemstatebackup%") +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, "process_path", process_path]) +| into write_ssa_detected_events(); +``` + +#### Associated Analytic Story +* [Ryuk Ransomware](/stories/ryuk_ransomware) +* [Ransomware](/stories/ransomware) + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint_Processess` datamodel. + +#### Required field +* _time +* dest_device_id +* process_name +* parent_process_name +* process_path +* dest_user_id +* process +* cmd_line + + +#### Kill Chain Phase +* Exploitation + + +#### Known False Positives +Administrators may modify the boot configuration. + + +#### RBA + +| Risk Score | Impact | Confidence | Message | +| ----------- | ----------- |--------------|--------------| +| 15.0 | 30 | 50 | An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system backups. | + + + + +#### Reference + +* [https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md) +* [https://thedfirreport.com/2020/10/08/ryuks-return/](https://thedfirreport.com/2020/10/08/ryuks-return/) +* [https://attack.mitre.org/techniques/T1490/](https://attack.mitre.org/techniques/T1490/) +* [https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin) + + + +#### Test Dataset +Replay any dataset to Splunk Enterprise by using our [`replay.py`](https://github.com/splunk/attack_data#using-replaypy) tool or the [UI](https://github.com/splunk/attack_data#using-ui). +Alternatively you can replay a dataset into a [Splunk Attack Range](https://github.com/splunk/attack_range#replay-dumps-into-attack-range-splunk-server) + + + + +[*source*](https://github.com/splunk/security_content/tree/develop/detections/endpoint/wbadmin_delete_system_backups.yml) \| *version*: **1** \ No newline at end of file diff --git a/docs/_stories/active_directory_lateral_movement.md b/docs/_stories/active_directory_lateral_movement.md new file mode 100644 index 0000000000..14d00cc808 --- /dev/null +++ b/docs/_stories/active_directory_lateral_movement.md @@ -0,0 +1,84 @@ +--- +title: "Active Directory Lateral Movement" +last_modified_at: 2021-12-09 +toc: true +toc_label: "" +tags: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + - Authentication + - Endpoint + - Network_Traffic +--- + +[Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} + +#### Description + +Detect and investigate tactics, techniques, and procedures around how attackers move laterally within an Active Directory environment. Since lateral movement is often a necessary step in a breach, it is important for cyber defenders to deploy detection coverage. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: [Authentication](https://docs.splunk.com/Documentation/CIM/latest/User/Authentication), [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) +- **Last Updated**: 2021-12-09 +- **Author**: David Dorsey, Mauricio Velazco Splunk +- **ID**: 399d65dc-1f08-499b-a259-aad9051f38ad + +#### Narrative + +Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation.\ +Indications of lateral movement in an Active Directory network can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, Service Control Manager, the DCOM protocol, WinRM or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or "crown jewels" to a persistent threat actor.\ +An adversary can use lateral movement for multiple purposes, including remote execution of tools, pivoting to additional systems, obtaining access to specific information or files, access to additional credentials, exfiltrating data, or delivering a secondary effect. Adversaries may use legitimate credentials alongside inherent network and operating-system functionality to remotely connect to other systems and remain under the radar of network defenders.\ +If there is evidence of lateral movement, it is imperative for analysts to collect evidence of the associated offending hosts. For example, an attacker might leverage host A to gain access to host B. From there, the attacker may try to move laterally to host C. In this example, the analyst should gather as much information as possible from all three hosts. \ + It is also important to collect authentication logs for each host, to ensure that the offending accounts are well-documented. Analysts should account for all processes to ensure that the attackers did not install unauthorized software. + +#### Detections + +| Name | Technique | Type | +| ----------- | ----------- |--------------| +| [Detect Activity Related to Pass the Hash Attacks](/endpoint/detect_activity_related_to_pass_the_hash_attacks/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | +| [Executable File Written in Administrative SMB Share](/endpoint/executable_file_written_in_administrative_smb_share/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | +| [Impacket Lateral Movement Commandline Parameters](/endpoint/impacket_lateral_movement_commandline_parameters/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Windows Service](/tags/#windows-service) | TTP | +| [Interactive Session on Remote Endpoint with PowerShell](/endpoint/interactive_session_on_remote_endpoint_with_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | +| [Mmc LOLBAS Execution Process Spawn](/endpoint/mmc_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | TTP | +| [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell) | TTP | +| [Potential Pass the Token or Hash Observed at the Destination Device](/endpoint/potential_pass_the_token_or_hash_observed_at_the_destination_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Potential Pass the Token or Hash Observed by an Event Collecting Device](/endpoint/potential_pass_the_token_or_hash_observed_by_an_event_collecting_device/) | [Use Alternate Authentication Material](/tags/#use-alternate-authentication-material), [Pass the Hash](/tags/#pass-the-hash) | TTP | +| [Randomly Generated Scheduled Task Name](/endpoint/randomly_generated_scheduled_task_name/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | Hunting | +| [Randomly Generated Windows Service Name](/endpoint/randomly_generated_windows_service_name/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | Hunting | +| [Remote Desktop Network Traffic](/network/remote_desktop_network_traffic/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Anomaly | +| [Remote Desktop Process Running On System](/endpoint/remote_desktop_process_running_on_system/) | [Remote Desktop Protocol](/tags/#remote-desktop-protocol), [Remote Services](/tags/#remote-services) | Hunting | +| [Remote Process Instantiation via DCOM and PowerShell](/endpoint/remote_process_instantiation_via_dcom_and_powershell/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | TTP | +| [Remote Process Instantiation via DCOM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_dcom_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model) | TTP | +| [Remote Process Instantiation via WMI](/endpoint/remote_process_instantiation_via_wmi/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | +| [Remote Process Instantiation via WMI and PowerShell](/endpoint/remote_process_instantiation_via_wmi_and_powershell/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | +| [Remote Process Instantiation via WMI and PowerShell Script Block](/endpoint/remote_process_instantiation_via_wmi_and_powershell_script_block/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | +| [Remote Process Instantiation via WinRM and PowerShell](/endpoint/remote_process_instantiation_via_winrm_and_powershell/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | +| [Remote Process Instantiation via WinRM and PowerShell Script Block](/endpoint/remote_process_instantiation_via_winrm_and_powershell_script_block/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | +| [Remote Process Instantiation via WinRM and Winrs](/endpoint/remote_process_instantiation_via_winrm_and_winrs/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | +| [Scheduled Task Creation on Remote Endpoint using At](/endpoint/scheduled_task_creation_on_remote_endpoint_using_at/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [At (Windows)](/tags/#at-(windows)) | TTP | +| [Scheduled Task Initiation on Remote Endpoint](/endpoint/scheduled_task_initiation_on_remote_endpoint/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Schtasks scheduling job on remote system](/endpoint/schtasks_scheduling_job_on_remote_system/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Services LOLBAS Execution Process Spawn](/endpoint/services_lolbas_execution_process_spawn/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | +| [Short Lived Scheduled Task](/endpoint/short_lived_scheduled_task/) | [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Svchost LOLBAS Execution Process Spawn](/endpoint/svchost_lolbas_execution_process_spawn/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Scheduled Task](/tags/#scheduled-task) | TTP | +| [Unusual Number of Computer Service Tickets Requested](/endpoint/unusual_number_of_computer_service_tickets_requested/) | [Valid Accounts](/tags/#valid-accounts) | Hunting | +| [Unusual Number of Remote Endpoint Authentication Events](/endpoint/unusual_number_of_remote_endpoint_authentication_events/) | [Valid Accounts](/tags/#valid-accounts) | Hunting | +| [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | +| [Windows Service Created With Suspicious Service Path](/endpoint/windows_service_created_with_suspicious_service_path/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | TTP | +| [Windows Service Created Within Public Path](/endpoint/windows_service_created_within_public_path/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | +| [Windows Service Creation on Remote Endpoint](/endpoint/windows_service_creation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | +| [Windows Service Initiation on Remote Endpoint](/endpoint/windows_service_initiation_on_remote_endpoint/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | +| [Wmiprsve LOLBAS Execution Process Spawn](/endpoint/wmiprsve_lolbas_execution_process_spawn/) | [Windows Management Instrumentation](/tags/#windows-management-instrumentation) | TTP | +| [Wsmprovhost LOLBAS Execution Process Spawn](/endpoint/wsmprovhost_lolbas_execution_process_spawn/) | [Remote Services](/tags/#remote-services), [Windows Remote Management](/tags/#windows-remote-management) | TTP | + +#### Reference + +* [https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html](https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html) +* [http://www.irongeek.com/i.php?page=videos/derbycon7/t405-hunting-lateral-movement-for-fun-and-profit-mauricio-velazco](http://www.irongeek.com/i.php?page=videos/derbycon7/t405-hunting-lateral-movement-for-fun-and-profit-mauricio-velazco) + + + +[*source*](https://github.com/splunk/security_content/tree/develop/stories/active_directory_lateral_movement.yml) \| *version*: **3** \ No newline at end of file diff --git a/docs/_stories/command_and_control.md b/docs/_stories/command_and_control.md index 1a8da8e6b8..69411e5d8c 100644 --- a/docs/_stories/command_and_control.md +++ b/docs/_stories/command_and_control.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes - Network_Resolution - Network_Traffic --- @@ -19,7 +20,7 @@ tags: Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) - **Last Updated**: 2018-06-01 - **Author**: Rico Valdez, Splunk - **ID**: 943773c6-c4de-4f38-89a8-0b92f98804d8 @@ -34,6 +35,7 @@ Because this communication is so critical for an adversary, they often use techn | Name | Technique | Type | | ----------- | ----------- |--------------| | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | | [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [Detect Large Outbound ICMP Packets](/network/detect_large_outbound_icmp_packets/) | [Non-Application Layer Protocol](/tags/#non-application-layer-protocol) | TTP | diff --git a/docs/_stories/credential_dumping.md b/docs/_stories/credential_dumping.md index a1b4611e43..1bae69e6b5 100644 --- a/docs/_stories/credential_dumping.md +++ b/docs/_stories/credential_dumping.md @@ -35,27 +35,14 @@ The detection searches in this Analytic Story monitor access to the Local Securi | Name | Technique | Type | | ----------- | ----------- |--------------| | [Access LSASS Memory for Dump Creation](/endpoint/access_lsass_memory_for_dump_creation/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Applying Stolen Credentials via Mimikatz modules](/endpoint/applying_stolen_credentials_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Modify Authentication Process](/tags/#modify-authentication-process), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | -| [Applying Stolen Credentials via PowerSploit modules](/endpoint/applying_stolen_credentials_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Access Token Manipulation](/tags/#access-token-manipulation), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism), [Compromise Client Software Binary](/tags/#compromise-client-software-binary), [Credentials from Password Stores](/tags/#credentials-from-password-stores), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | -| [Assessment of Credential Strength via DSInternals modules](/endpoint/assessment_of_credential_strength_via_dsinternals_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation), [Account Discovery](/tags/#account-discovery), [Password Policy Discovery](/tags/#password-policy-discovery), [Unsecured Credentials](/tags/#unsecured-credentials), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | | [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | +| [Attempted Credential Dump From Registry via Reg exe](/endpoint/attempted_credential_dump_from_registry_via_reg_exe/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Security Account Manager](/tags/#security-account-manager) | TTP | | [Create Remote Thread into LSASS](/endpoint/create_remote_thread_into_lsass/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Creation of Shadow Copy](/endpoint/creation_of_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Creation of Shadow Copy with wmic and powershell](/endpoint/creation_of_shadow_copy_with_wmic_and_powershell/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Creation of lsass Dump with Taskmgr](/endpoint/creation_of_lsass_dump_with_taskmgr/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Dumping via Copy Command from Shadow Copy](/endpoint/credential_dumping_via_copy_command_from_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Credential Dumping via Symlink to Shadow Copy](/endpoint/credential_dumping_via_symlink_to_shadow_copy/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of FGDump and CacheDump with s option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of FGDump and CacheDump with v option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of Lazagne command line options](/endpoint/credential_extraction_indicative_of_lazagne_command_line_options/) | [OS Credential Dumping](/tags/#os-credential-dumping), [Credentials from Password Stores](/tags/#credentials-from-password-stores) | TTP | -| [Credential Extraction indicative of use of DSInternals credential conversion modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of DSInternals modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of Mimikatz modules](/endpoint/credential_extraction_indicative_of_use_of_mimikatz_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of PowerSploit modules](/endpoint/credential_extraction_indicative_of_use_of_powersploit_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction native Microsoft debuggers peek into the kernel](/endpoint/credential_extraction_native_microsoft_debuggers_peek_into_the_kernel/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction native Microsoft debuggers via z command line option](/endpoint/credential_extraction_native_microsoft_debuggers_via_z_command_line_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](/endpoint/credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Copy of ShadowCopy with Script Block Logging](/endpoint/detect_copy_of_shadowcopy_with_script_block_logging/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Credential Dumping through LSASS access](/endpoint/detect_credential_dumping_through_lsass_access/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Dump LSASS Memory using comsvcs](/endpoint/detect_dump_lsass_memory_using_comsvcs/) | [NTDS](/tags/#ntds), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | diff --git a/docs/_stories/darkside_ransomware.md b/docs/_stories/darkside_ransomware.md index 95ab2cb837..f57b0c89ec 100644 --- a/docs/_stories/darkside_ransomware.md +++ b/docs/_stories/darkside_ransomware.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -17,7 +18,7 @@ tags: Leverage searches that allow you to detect and investigate unusual activities that might relate to the DarkSide Ransomware - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) - **Last Updated**: 2021-05-12 - **Author**: Bhavin Patel, Splunk - **ID**: 507edc74-13d5-4339-878e-b9114ded1f35 @@ -40,6 +41,7 @@ This story addresses Darkside ransomware. This ransomware payload has many simil | [Detect Mimikatz Using Loaded Images](/endpoint/detect_mimikatz_using_loaded_images/) | [LSASS Memory](/tags/#lsass-memory), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect PsExec With accepteula Flag](/endpoint/detect_psexec_with_accepteula_flag/) | [Remote Services](/tags/#remote-services), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | | [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | +| [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | | [Detect Renamed PSExec](/endpoint/detect_renamed_psexec/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Hunting | | [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration) | Hunting | | [Extraction of Registry Hives](/endpoint/extraction_of_registry_hives/) | [Security Account Manager](/tags/#security-account-manager), [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | diff --git a/docs/_stories/data_exfiltration.md b/docs/_stories/data_exfiltration.md index 0625e110f5..ec71ecb49a 100644 --- a/docs/_stories/data_exfiltration.md +++ b/docs/_stories/data_exfiltration.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes - Network_Traffic --- @@ -18,7 +19,7 @@ tags: The stealing of data by an adversary. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) - **Last Updated**: 2020-10-21 - **Author**: Shannon Davis, Splunk - **ID**: 66b0fe0c-1351-11eb-adc1-0242ac120002 @@ -32,6 +33,7 @@ Exfiltration comes in many flavors. Adversaries can collect data over encrypted | Name | Technique | Type | | ----------- | ----------- |--------------| | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [Detect SNICat SNI Exfiltration](/network/detect_snicat_sni_exfiltration/) | [Exfiltration Over C2 Channel](/tags/#exfiltration-over-c2-channel) | TTP | | [Detect shared ec2 snapshot](/cloud/detect_shared_ec2_snapshot/) | [Transfer Data to Cloud Account](/tags/#transfer-data-to-cloud-account) | TTP | | [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | diff --git a/docs/_stories/dynamic_dns.md b/docs/_stories/dynamic_dns.md index 7b06511608..fcd1b96af5 100644 --- a/docs/_stories/dynamic_dns.md +++ b/docs/_stories/dynamic_dns.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes - Network_Resolution --- @@ -18,7 +19,7 @@ tags: Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and deny lists. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) - **Last Updated**: 2018-09-06 - **Author**: Bhavin Patel, Splunk - **ID**: 8169f17b-ef68-4b59-aae8-586907301221 @@ -32,6 +33,7 @@ Dynamic DNS services (DDNS) are legitimate low-cost or free services that allow | Name | Technique | Type | | ----------- | ----------- |--------------| | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise) | TTP | | [Excessive Usage of NSLOOKUP App](/endpoint/excessive_usage_of_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | diff --git a/docs/_stories/ingress_tool_transfer.md b/docs/_stories/ingress_tool_transfer.md index 39e7418f00..6ce31ca540 100644 --- a/docs/_stories/ingress_tool_transfer.md +++ b/docs/_stories/ingress_tool_transfer.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -17,7 +18,7 @@ tags: Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) - **Last Updated**: 2021-03-24 - **Author**: Michael Haag, Splunk - **ID**: b3782036-8cbd-11eb-9d8e-acde48001122 @@ -38,6 +39,7 @@ Ingress tool transfer is a Technique under tactic Command and Control. Behaviors | [Suspicious Curl Network Connection](/endpoint/suspicious_curl_network_connection/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Windows Curl Download to Suspicious Path](/endpoint/windows_curl_download_to_suspicious_path/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | | [Windows Curl Upload to Remote Destination](/endpoint/windows_curl_upload_to_remote_destination/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | +| [Windows Curl Upload to Remote Destination](/endpoint/windows_curl_upload_to_remote_destination/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | #### Reference diff --git a/docs/_stories/malicious_powershell.md b/docs/_stories/malicious_powershell.md index f4ca0073c3..0b0cea91f4 100644 --- a/docs/_stories/malicious_powershell.md +++ b/docs/_stories/malicious_powershell.md @@ -8,7 +8,6 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint - - Endpoint_Processes --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -18,7 +17,7 @@ tags: Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) - **Last Updated**: 2017-08-23 - **Author**: David Dorsey, Splunk - **ID**: 2c8ff66e-0b57-42af-8ad7-912438a403fc @@ -44,18 +43,12 @@ Most recently we have added new content related to PowerShell Script Block loggi | ----------- | ----------- |--------------| | [Any Powershell DownloadFile](/endpoint/any_powershell_downloadfile/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Any Powershell DownloadString](/endpoint/any_powershell_downloadstring/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | -| [Credential Extraction indicative of use of DSInternals credential conversion modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of DSInternals modules](/endpoint/credential_extraction_indicative_of_use_of_dsinternals_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of PowerSploit modules](/endpoint/credential_extraction_indicative_of_use_of_powersploit_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](/endpoint/credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Empire with PowerShell Script Block Logging](/endpoint/detect_empire_with_powershell_script_block_logging/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [Detect Mimikatz With PowerShell Script Block Logging](/endpoint/detect_mimikatz_with_powershell_script_block_logging/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Illegal Access To User Content via PowerSploit modules](/endpoint/illegal_access_to_user_content_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Screen Capture](/tags/#screen-capture), [Audio Capture](/tags/#audio-capture), [Remote Service Session Hijacking](/tags/#remote-service-session-hijacking) | TTP | -| [Illegal Privilege Elevation and Persistence via PowerSploit modules](/endpoint/illegal_privilege_elevation_and_persistence_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Illegal Service and Process Control via PowerSploit modules](/endpoint/illegal_service_and_process_control_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | | [Malicious PowerShell Process - Connect To Internet With Hidden Window](/endpoint/malicious_powershell_process_-_connect_to_internet_with_hidden_window/) | [PowerShell](/tags/#powershell), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter) | Hunting | | [Malicious PowerShell Process - Encoded Command](/endpoint/malicious_powershell_process_-_encoded_command/) | [Obfuscated Files or Information](/tags/#obfuscated-files-or-information) | Hunting | | [Malicious PowerShell Process With Obfuscation Techniques](/endpoint/malicious_powershell_process_with_obfuscation_techniques/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | +| [Possible Lateral Movement PowerShell Spawn](/endpoint/possible_lateral_movement_powershell_spawn/) | [Remote Services](/tags/#remote-services), [Distributed Component Object Model](/tags/#distributed-component-object-model), [Windows Remote Management](/tags/#windows-remote-management), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Scheduled Task](/tags/#scheduled-task), [Windows Service](/tags/#windows-service), [PowerShell](/tags/#powershell) | TTP | | [PowerShell 4104 Hunting](/endpoint/powershell_4104_hunting/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | Hunting | | [PowerShell Domain Enumeration](/endpoint/powershell_domain_enumeration/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | | [PowerShell Loading DotNET into Memory via System Reflection Assembly](/endpoint/powershell_loading_dotnet_into_memory_via_system_reflection_assembly/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [PowerShell](/tags/#powershell) | TTP | diff --git a/docs/_stories/ransomware.md b/docs/_stories/ransomware.md index ef54043c0a..8f1d66b5d3 100644 --- a/docs/_stories/ransomware.md +++ b/docs/_stories/ransomware.md @@ -36,9 +36,10 @@ Ransomware is an ever-present risk to the enterprise, wherein an infected host e | [Allow File And Printing Sharing In Firewall](/endpoint/allow_file_and_printing_sharing_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Allow Network Discovery In Firewall](/endpoint/allow_network_discovery_in_firewall/) | [Disable or Modify Cloud Firewall](/tags/#disable-or-modify-cloud-firewall), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Allow Operation with Consent Admin](/endpoint/allow_operation_with_consent_admin/) | [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | -| [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop) | TTP | +| [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | +| [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [CMLUA Or CMSTPLUA UAC Bypass](/endpoint/cmlua_or_cmstplua_uac_bypass/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [Clear Unallocated Sector Using Cipher App](/endpoint/clear_unallocated_sector_using_cipher_app/) | [File Deletion](/tags/#file-deletion), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | @@ -48,6 +49,7 @@ Ransomware is an ever-present risk to the enterprise, wherein an infected host e | [Delete ShadowCopy With PowerShell](/endpoint/delete_shadowcopy_with_powershell/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | +| [Detect RClone Command-Line Usage](/endpoint/detect_rclone_command-line_usage/) | [Automated Exfiltration](/tags/#automated-exfiltration) | TTP | | [Detect Renamed RClone](/endpoint/detect_renamed_rclone/) | [Automated Exfiltration](/tags/#automated-exfiltration) | Hunting | | [Detect SharpHound Command-Line Arguments](/endpoint/detect_sharphound_command-line_arguments/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | | [Detect SharpHound File Modifications](/endpoint/detect_sharphound_file_modifications/) | [Domain Account](/tags/#domain-account), [Local Groups](/tags/#local-groups), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Local Account](/tags/#local-account), [Account Discovery](/tags/#account-discovery), [Domain Groups](/tags/#domain-groups), [Permission Groups Discovery](/tags/#permission-groups-discovery) | TTP | @@ -55,13 +57,14 @@ Ransomware is an ever-present risk to the enterprise, wherein an infected host e | [Disable AMSI Through Registry](/endpoint/disable_amsi_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable ETW Through Registry](/endpoint/disable_etw_through_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disable Logs Using WevtUtil](/endpoint/disable_logs_using_wevtutil/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | -| [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop) | TTP | +| [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop), [Valid Accounts](/tags/#valid-accounts) | TTP | | [Disable Windows Behavior Monitoring](/endpoint/disable_windows_behavior_monitoring/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Excessive Service Stop Attempt](/endpoint/excessive_service_stop_attempt/) | [Service Stop](/tags/#service-stop) | Anomaly | | [Excessive Usage Of Net App](/endpoint/excessive_usage_of_net_app/) | [Account Access Removal](/tags/#account-access-removal) | Anomaly | | [Excessive Usage Of SC Service Utility](/endpoint/excessive_usage_of_sc_service_utility/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | | [Execute Javascript With Jscript COM CLSID](/endpoint/execute_javascript_with_jscript_com_clsid/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Visual Basic](/tags/#visual-basic) | TTP | | [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | +| [Fsutil Zeroing File](/endpoint/fsutil_zeroing_file/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [ICACLS Grant Command](/endpoint/icacls_grant_command/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | | [Known Services Killed by Ransomware](/endpoint/known_services_killed_by_ransomware/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Modification Of Wallpaper](/endpoint/modification_of_wallpaper/) | [Defacement](/tags/#defacement) | TTP | @@ -95,6 +98,7 @@ Ransomware is an ever-present risk to the enterprise, wherein an infected host e | [Unusually Long Command Line](/endpoint/unusually_long_command_line/) | | Anomaly | | [Unusually Long Command Line - MLTK](/endpoint/unusually_long_command_line_-_mltk/) | | Anomaly | | [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | +| [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Wbemprox COM Object Execution](/endpoint/wbemprox_com_object_execution/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [CMSTP](/tags/#cmstp) | TTP | | [WevtUtil Usage To Clear Logs](/endpoint/wevtutil_usage_to_clear_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | | [Wevtutil Usage To Disable Logs](/endpoint/wevtutil_usage_to_disable_logs/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | diff --git a/docs/_stories/ryuk_ransomware.md b/docs/_stories/ryuk_ransomware.md index eda620fe81..ac8145245f 100644 --- a/docs/_stories/ryuk_ransomware.md +++ b/docs/_stories/ryuk_ransomware.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes - Network_Traffic --- @@ -18,7 +19,7 @@ tags: Leverage searches that allow you to detect and investigate unusual activities that might relate to the Ryuk ransomware, including looking for file writes associated with Ryuk, Stopping Security Access Manager, DisableAntiSpyware registry key modification, suspicious psexec use, and more. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses), [Network_Traffic](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkTraffic) - **Last Updated**: 2020-11-06 - **Author**: Jose Hernandez, Splunk - **ID**: 507edc74-13d5-4339-878e-b9744ded1f35 @@ -32,6 +33,7 @@ Cybersecurity Infrastructure Security Agency (CISA) released Alert (AA20-302A) o | Name | Technique | Type | | ----------- | ----------- |--------------| | [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | +| [BCDEdit Failure Recovery Modification](/endpoint/bcdedit_failure_recovery_modification/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [Common Ransomware Extensions](/endpoint/common_ransomware_extensions/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [Common Ransomware Notes](/endpoint/common_ransomware_notes/) | [Data Destruction](/tags/#data-destruction) | Hunting | | [NLTest Domain Trust Discovery](/endpoint/nltest_domain_trust_discovery/) | [Domain Trust Discovery](/tags/#domain-trust-discovery) | TTP | @@ -42,6 +44,7 @@ Cybersecurity Infrastructure Security Agency (CISA) released Alert (AA20-302A) o | [Spike in File Writes](/endpoint/spike_in_file_writes/) | | Anomaly | | [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | | [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | +| [WBAdmin Delete System Backups](/endpoint/wbadmin_delete_system_backups/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | | [WinEvent Scheduled Task Created Within Public Path](/endpoint/winevent_scheduled_task_created_within_public_path/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [WinEvent Scheduled Task Created to Spawn Shell](/endpoint/winevent_scheduled_task_created_to_spawn_shell/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Windows DisableAntiSpyware Registry](/endpoint/windows_disableantispyware_registry/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | diff --git a/docs/_stories/suspicious_dns_traffic.md b/docs/_stories/suspicious_dns_traffic.md index 01df9d4326..225237c3c9 100644 --- a/docs/_stories/suspicious_dns_traffic.md +++ b/docs/_stories/suspicious_dns_traffic.md @@ -8,6 +8,7 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint + - Endpoint_Processes - Network_Resolution --- @@ -18,7 +19,7 @@ tags: Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses), [Network_Resolution](https://docs.splunk.com/Documentation/CIM/latest/User/NetworkResolution) - **Last Updated**: 2017-09-18 - **Author**: Rico Valdez, Splunk - **ID**: 3c3835c0-255d-4f9e-ab84-e29ec9ec9b56 @@ -32,6 +33,7 @@ Although DNS is one of the fundamental underlying protocols that make the Intern | Name | Technique | Type | | ----------- | ----------- |--------------| | [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | +| [DNS Exfiltration Using Nslookup App](/endpoint/dns_exfiltration_using_nslookup_app/) | [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | TTP | | [DNS Query Length Outliers - MLTK](/network/dns_query_length_outliers_-_mltk/) | [DNS](/tags/#dns), [Application Layer Protocol](/tags/#application-layer-protocol) | Anomaly | | [DNS Query Length With High Standard Deviation](/network/dns_query_length_with_high_standard_deviation/) | [Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol](/tags/#exfiltration-over-unencrypted/obfuscated-non-c2-protocol), [Exfiltration Over Alternative Protocol](/tags/#exfiltration-over-alternative-protocol) | Anomaly | | [Detect hosts connecting to dynamic domain providers](/network/detect_hosts_connecting_to_dynamic_domain_providers/) | [Drive-by Compromise](/tags/#drive-by-compromise) | TTP | diff --git a/docs/_stories/unusual_processes.md b/docs/_stories/unusual_processes.md index 8aa471f5c3..ad289fd919 100644 --- a/docs/_stories/unusual_processes.md +++ b/docs/_stories/unusual_processes.md @@ -34,14 +34,9 @@ In the event an unusual process is identified, it is imperative to better unders | Name | Technique | Type | | ----------- | ----------- |--------------| | [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | TTP | -| [Credential Extraction indicative of FGDump and CacheDump with s option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of FGDump and CacheDump with v option](/endpoint/credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction indicative of use of Mimikatz modules](/endpoint/credential_extraction_indicative_of_use_of_mimikatz_modules/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction native Microsoft debuggers peek into the kernel](/endpoint/credential_extraction_native_microsoft_debuggers_peek_into_the_kernel/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | -| [Credential Extraction native Microsoft debuggers via z command line option](/endpoint/credential_extraction_native_microsoft_debuggers_via_z_command_line_option/) | [OS Credential Dumping](/tags/#os-credential-dumping) | TTP | | [Detect Rare Executables](/endpoint/detect_rare_executables/) | | Anomaly | | [Detect processes used for System Network Configuration Discovery](/endpoint/detect_processes_used_for_system_network_configuration_discovery/) | [System Network Configuration Discovery](/tags/#system-network-configuration-discovery) | TTP | -| [First time seen command line argument](/endpoint/first_time_seen_command_line_argument/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Regsvr32](/tags/#regsvr32), [Indirect Command Execution](/tags/#indirect-command-execution) | Anomaly | +| [First time seen command line argument](/endpoint/first_time_seen_command_line_argument/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Indirect Command Execution](/tags/#indirect-command-execution) | Anomaly | | [More than usual number of LOLBAS applications in short time period](/endpoint/more_than_usual_number_of_lolbas_applications_in_short_time_period/) | [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | | [Rare Parent-Child Process Relationship](/endpoint/rare_parent-child_process_relationship/) | [Exploitation for Client Execution](/tags/#exploitation-for-client-execution), [Command and Scripting Interpreter](/tags/#command-and-scripting-interpreter), [Scheduled Task/Job](/tags/#scheduled-task/job), [Software Deployment Tools](/tags/#software-deployment-tools) | Anomaly | | [RunDLL Loading DLL By Ordinal](/endpoint/rundll_loading_dll_by_ordinal/) | [Signed Binary Proxy Execution](/tags/#signed-binary-proxy-execution), [Rundll32](/tags/#rundll32) | TTP | diff --git a/docs/_stories/windows_discovery_techniques.md b/docs/_stories/windows_discovery_techniques.md index 56c035fb1d..bad982e627 100644 --- a/docs/_stories/windows_discovery_techniques.md +++ b/docs/_stories/windows_discovery_techniques.md @@ -8,7 +8,7 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - - Endpoint_Processes + - Endpoint --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -18,7 +18,7 @@ tags: Monitors for behaviors associated with adversaries discovering objects in the environment that can be leveraged in the progression of the attack. - **Product**: Splunk Behavioral Analytics, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) - **Last Updated**: 2021-03-04 - **Author**: Michael Hart, Splunk - **ID**: f7aba570-7d59-11eb-825e-acde48001122 @@ -31,21 +31,7 @@ Attackers may not have much if any insight into their target's environment befor | Name | Technique | Type | | ----------- | ----------- |--------------| -| [Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules](/endpoint/reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Discovery](/tags/#account-discovery), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Reconnaissance and Access to Accounts and Groups via Mimikatz modules](/endpoint/reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Discovery](/tags/#account-discovery), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules](/endpoint/reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules/) | [Trusted Relationship](/tags/#trusted-relationship), [Domain Trust Discovery](/tags/#domain-trust-discovery), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Gather Victim Org Information](/tags/#gather-victim-org-information), [Active Scanning](/tags/#active-scanning) | TTP | -| [Reconnaissance and Access to Computers and Domains via PowerSploit modules](/endpoint/reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Account Discovery](/tags/#account-discovery) | TTP | -| [Reconnaissance and Access to Computers via Mimikatz modules](/endpoint/reconnaissance_and_access_to_computers_via_mimikatz_modules/) | [Gather Victim Host Information](/tags/#gather-victim-host-information) | TTP | -| [Reconnaissance and Access to Operating System Elements via PowerSploit modules](/endpoint/reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules/) | [Process Discovery](/tags/#process-discovery), [File and Directory Discovery](/tags/#file-and-directory-discovery), [Software](/tags/#software), [Network Service Scanning](/tags/#network-service-scanning), [Query Registry](/tags/#query-registry), [System Service Discovery](/tags/#system-service-discovery), [Windows Management Instrumentation](/tags/#windows-management-instrumentation), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Software Discovery](/tags/#software-discovery) | TTP | -| [Reconnaissance and Access to Processes and Services via Mimikatz modules](/endpoint/reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules/) | [System Service Discovery](/tags/#system-service-discovery), [Network Service Scanning](/tags/#network-service-scanning), [Process Discovery](/tags/#process-discovery) | TTP | -| [Reconnaissance and Access to Shared Resources via Mimikatz modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_mimikatz_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Reconnaissance and Access to Shared Resources via PowerSploit modules](/endpoint/reconnaissance_and_access_to_shared_resources_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Reconnaissance of Access and Persistence Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | -| [Reconnaissance of Connectivity via PowerSploit modules](/endpoint/reconnaissance_of_connectivity_via_powersploit_modules/) | [Remote Services](/tags/#remote-services), [Data from Network Shared Drive](/tags/#data-from-network-shared-drive), [Network Share Discovery](/tags/#network-share-discovery), [SMB/Windows Admin Shares](/tags/#smb/windows-admin-shares) | TTP | -| [Reconnaissance of Credential Stores and Services via Mimikatz modules](/endpoint/reconnaissance_of_credential_stores_and_services_via_mimikatz_modules/) | [Account Manipulation](/tags/#account-manipulation), [Domain Properties](/tags/#domain-properties), [Valid Accounts](/tags/#valid-accounts), [Credentials](/tags/#credentials), [Gather Victim Network Information](/tags/#gather-victim-network-information), [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Gather Victim Identity Information](/tags/#gather-victim-identity-information), [Network Trust Dependencies](/tags/#network-trust-dependencies) | TTP | -| [Reconnaissance of Defensive Tools via PowerSploit modules](/endpoint/reconnaissance_of_defensive_tools_via_powersploit_modules/) | [Software](/tags/#software), [Vulnerability Scanning](/tags/#vulnerability-scanning), [Gather Victim Host Information](/tags/#gather-victim-host-information), [Active Scanning](/tags/#active-scanning) | TTP | -| [Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules](/endpoint/reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules](/endpoint/reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules/) | [Create or Modify System Process](/tags/#create-or-modify-system-process), [Process Injection](/tags/#process-injection), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | +| [Net Localgroup Discovery](/endpoint/net_localgroup_discovery/) | [Permission Groups Discovery](/tags/#permission-groups-discovery), [Local Groups](/tags/#local-groups) | Hunting | #### Reference diff --git a/docs/_stories/windows_log_manipulation.md b/docs/_stories/windows_log_manipulation.md index 7c892f1278..07b1bc8d8b 100644 --- a/docs/_stories/windows_log_manipulation.md +++ b/docs/_stories/windows_log_manipulation.md @@ -33,7 +33,6 @@ The Analytic Story gives users two different ways to detect manipulation of Wind | Name | Technique | Type | | ----------- | ----------- |--------------| | [Deleting Shadow Copies](/endpoint/deleting_shadow_copies/) | [Inhibit System Recovery](/tags/#inhibit-system-recovery) | TTP | -| [Illegal Deletion of Logs via Mimikatz modules](/endpoint/illegal_deletion_of_logs_via_mimikatz_modules/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [Suspicious Event Log Service Behavior](/endpoint/suspicious_event_log_service_behavior/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host), [Clear Windows Event Logs](/tags/#clear-windows-event-logs) | TTP | | [Suspicious wevtutil Usage](/endpoint/suspicious_wevtutil_usage/) | [Clear Windows Event Logs](/tags/#clear-windows-event-logs), [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | | [USN Journal Deletion](/endpoint/usn_journal_deletion/) | [Indicator Removal on Host](/tags/#indicator-removal-on-host) | TTP | diff --git a/docs/_stories/windows_persistence_techniques.md b/docs/_stories/windows_persistence_techniques.md index e481599407..2ac45b788a 100644 --- a/docs/_stories/windows_persistence_techniques.md +++ b/docs/_stories/windows_persistence_techniques.md @@ -8,7 +8,6 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint - - Endpoint_Processes --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -18,7 +17,7 @@ tags: Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) - **Last Updated**: 2018-05-31 - **Author**: Bhavin Patel, Splunk - **ID**: 30874d4f-20a1-488f-85ec-5d52ef74e3f9 @@ -37,11 +36,6 @@ Maintaining persistence is one of the first steps taken by attackers after the i | [Detect Path Interception By Creation Of program exe](/endpoint/detect_path_interception_by_creation_of_program_exe/) | [Path Interception by Unquoted Path](/tags/#path-interception-by-unquoted-path), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | | [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Hiding Files And Directories With Attrib exe](/endpoint/hiding_files_and_directories_with_attrib_exe/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification), [Windows File and Directory Permissions Modification](/tags/#windows-file-and-directory-permissions-modification) | TTP | -| [Illegal Account Creation via PowerSploit modules](/endpoint/illegal_account_creation_via_powersploit_modules/) | [Establish Accounts](/tags/#establish-accounts) | TTP | -| [Illegal Enabling or Disabling of Accounts via DSInternals modules](/endpoint/illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Illegal Management of Active Directory Elements and Policies via DSInternals modules](/endpoint/illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules/) | [Account Manipulation](/tags/#account-manipulation), [Rogue Domain Controller](/tags/#rogue-domain-controller), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Illegal Management of Computers and Active Directory Elements via PowerSploit modules](/endpoint/illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules/) | [Account Manipulation](/tags/#account-manipulation), [Rogue Domain Controller](/tags/#rogue-domain-controller), [Domain Policy Modification](/tags/#domain-policy-modification) | TTP | -| [Illegal Privilege Elevation and Persistence via PowerSploit modules](/endpoint/illegal_privilege_elevation_and_persistence_via_powersploit_modules/) | [Scheduled Task/Job](/tags/#scheduled-task/job), [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | TTP | | [Monitor Registry Keys for Print Monitors](/endpoint/monitor_registry_keys_for_print_monitors/) | [Port Monitors](/tags/#port-monitors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | | [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | @@ -53,9 +47,6 @@ Maintaining persistence is one of the first steps taken by attackers after the i | [Schedule Task with Rundll32 Command Trigger](/endpoint/schedule_task_with_rundll32_command_trigger/) | [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Schtasks used for forcing a reboot](/endpoint/schtasks_used_for_forcing_a_reboot/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | TTP | | [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver) | TTP | -| [Setting Credentials via DSInternals modules](/endpoint/setting_credentials_via_dsinternals_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Setting Credentials via Mimikatz modules](/endpoint/setting_credentials_via_mimikatz_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | -| [Setting Credentials via PowerSploit modules](/endpoint/setting_credentials_via_powersploit_modules/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation), [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Shim Database File Creation](/endpoint/shim_database_file_creation/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Shim Database Installation With Suspicious Parameters](/endpoint/shim_database_installation_with_suspicious_parameters/) | [Application Shimming](/tags/#application-shimming), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Suspicious Scheduled Task from Public Directory](/endpoint/suspicious_scheduled_task_from_public_directory/) | [Scheduled Task](/tags/#scheduled-task), [Scheduled Task/Job](/tags/#scheduled-task/job) | Anomaly | diff --git a/docs/_stories/windows_privilege_escalation.md b/docs/_stories/windows_privilege_escalation.md index d1d3a40b8d..1cd79462b7 100644 --- a/docs/_stories/windows_privilege_escalation.md +++ b/docs/_stories/windows_privilege_escalation.md @@ -8,7 +8,6 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint - - Endpoint_Processes --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -18,7 +17,7 @@ tags: Monitor for and investigate activities that may be associated with a Windows privilege-escalation attack, including unusual processes running on endpoints, modified registry keys, and more. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) - **Last Updated**: 2020-02-04 - **Author**: David Dorsey, Splunk - **ID**: 644e22d3-598a-429c-a007-16fdb802cae5 @@ -35,12 +34,10 @@ Privilege escalation is a "land-and-expand" technique, wherein an adversary gain | [Change Default File Association](/endpoint/change_default_file_association/) | [Change Default File Association](/tags/#change-default-file-association), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Child Processes of Spoolsv exe](/endpoint/child_processes_of_spoolsv_exe/) | [Exploitation for Privilege Escalation](/tags/#exploitation-for-privilege-escalation) | TTP | | [ETW Registry Disabled](/endpoint/etw_registry_disabled/) | [Indicator Blocking](/tags/#indicator-blocking), [Trusted Developer Utilities Proxy Execution](/tags/#trusted-developer-utilities-proxy-execution), [Impair Defenses](/tags/#impair-defenses) | TTP | -| [Illegal Privilege Elevation via Mimikatz modules](/endpoint/illegal_privilege_elevation_via_mimikatz_modules/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Abuse Elevation Control Mechanism](/tags/#abuse-elevation-control-mechanism) | TTP | | [Kerberoasting spn request with RC4 encryption](/endpoint/kerberoasting_spn_request_with_rc4_encryption/) | [Kerberoasting](/tags/#kerberoasting), [Steal or Forge Kerberos Tickets](/tags/#steal-or-forge-kerberos-tickets) | TTP | | [Logon Script Event Trigger Execution](/endpoint/logon_script_event_trigger_execution/) | [Boot or Logon Initialization Scripts](/tags/#boot-or-logon-initialization-scripts), [Logon Script (Windows)](/tags/#logon-script-(windows)) | TTP | | [Overwriting Accessibility Binaries](/endpoint/overwriting_accessibility_binaries/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Accessibility Features](/tags/#accessibility-features) | TTP | | [Print Processor Registry Autostart](/endpoint/print_processor_registry_autostart/) | [Print Processors](/tags/#print-processors), [Boot or Logon Autostart Execution](/tags/#boot-or-logon-autostart-execution) | TTP | -| [Probing Access with Stolen Credentials via PowerSploit modules](/endpoint/probing_access_with_stolen_credentials_via_powersploit_modules/) | [Valid Accounts](/tags/#valid-accounts), [Account Manipulation](/tags/#account-manipulation) | TTP | | [Registry Keys Used For Privilege Escalation](/endpoint/registry_keys_used_for_privilege_escalation/) | [Image File Execution Options Injection](/tags/#image-file-execution-options-injection), [Event Triggered Execution](/tags/#event-triggered-execution) | TTP | | [Runas Execution in CommandLine](/endpoint/runas_execution_in_commandline/) | [Access Token Manipulation](/tags/#access-token-manipulation), [Token Impersonation/Theft](/tags/#token-impersonation/theft) | Hunting | | [Screensaver Event Trigger Execution](/endpoint/screensaver_event_trigger_execution/) | [Event Triggered Execution](/tags/#event-triggered-execution), [Screensaver](/tags/#screensaver) | TTP | diff --git a/docs/_stories/windows_service_abuse.md b/docs/_stories/windows_service_abuse.md index 751b73cacf..74d1a37807 100644 --- a/docs/_stories/windows_service_abuse.md +++ b/docs/_stories/windows_service_abuse.md @@ -8,7 +8,6 @@ tags: - Splunk Enterprise Security - Splunk Cloud - Endpoint - - Endpoint_Processes --- [Try in Splunk Security Cloud](https://www.splunk.com/en_us/cyber-security.html){: .btn .btn--success} @@ -18,7 +17,7 @@ tags: Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint), [Endpoint_Processes](https://docs.splunk.com/Documentation/CIM/latest/User/EndpointProcesses) +- **Datamodel**: [Endpoint](https://docs.splunk.com/Documentation/CIM/latest/User/Endpoint) - **Last Updated**: 2017-11-02 - **Author**: Rico Valdez, Splunk - **ID**: 6dbd810e-f66d-414b-8dfc-e46de55cbfe2 @@ -32,8 +31,6 @@ The Windows operating system uses a services architecture to allow for running c | Name | Technique | Type | | ----------- | ----------- |--------------| | [First Time Seen Running Windows Service](/endpoint/first_time_seen_running_windows_service/) | [System Services](/tags/#system-services), [Service Execution](/tags/#service-execution) | Anomaly | -| [Illegal Service and Process Control via Mimikatz modules](/endpoint/illegal_service_and_process_control_via_mimikatz_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | -| [Illegal Service and Process Control via PowerSploit modules](/endpoint/illegal_service_and_process_control_via_powersploit_modules/) | [Process Injection](/tags/#process-injection), [Native API](/tags/#native-api), [System Services](/tags/#system-services) | TTP | | [Reg exe Manipulating Windows Services Registry Keys](/endpoint/reg_exe_manipulating_windows_services_registry_keys/) | [Services Registry Permissions Weakness](/tags/#services-registry-permissions-weakness), [Hijack Execution Flow](/tags/#hijack-execution-flow) | TTP | | [Sc exe Manipulating Windows Services](/endpoint/sc_exe_manipulating_windows_services/) | [Windows Service](/tags/#windows-service), [Create or Modify System Process](/tags/#create-or-modify-system-process) | TTP | diff --git a/docs/_stories/xmrig.md b/docs/_stories/xmrig.md index 0e4c24f7e0..731b48a0d3 100644 --- a/docs/_stories/xmrig.md +++ b/docs/_stories/xmrig.md @@ -32,12 +32,12 @@ XMRig is a high performance, open source, cross platform RandomX, KawPow, Crypto | Name | Technique | Type | | ----------- | ----------- |--------------| | [Attacker Tools On Endpoint](/endpoint/attacker_tools_on_endpoint/) | [Match Legitimate Name or Location](/tags/#match-legitimate-name-or-location), [Masquerading](/tags/#masquerading), [OS Credential Dumping](/tags/#os-credential-dumping), [Active Scanning](/tags/#active-scanning) | TTP | -| [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop) | TTP | +| [Attempt To Delete Services](/endpoint/attempt_to_delete_services/) | [Service Stop](/tags/#service-stop), [Create or Modify System Process](/tags/#create-or-modify-system-process), [Windows Service](/tags/#windows-service) | TTP | | [Attempt To Disable Services](/endpoint/attempt_to_disable_services/) | [Service Stop](/tags/#service-stop) | TTP | | [Delete A Net User](/endpoint/delete_a_net_user/) | [Account Access Removal](/tags/#account-access-removal) | Anomaly | | [Deleting Of Net Users](/endpoint/deleting_of_net_users/) | [Account Access Removal](/tags/#account-access-removal) | TTP | | [Deny Permission using Cacls Utility](/endpoint/deny_permission_using_cacls_utility/) | [File and Directory Permissions Modification](/tags/#file-and-directory-permissions-modification) | TTP | -| [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop) | TTP | +| [Disable Net User Account](/endpoint/disable_net_user_account/) | [Service Stop](/tags/#service-stop), [Valid Accounts](/tags/#valid-accounts) | TTP | | [Disable Windows App Hotkeys](/endpoint/disable_windows_app_hotkeys/) | [Disable or Modify Tools](/tags/#disable-or-modify-tools), [Impair Defenses](/tags/#impair-defenses) | TTP | | [Disabling Net User Account](/endpoint/disabling_net_user_account/) | [Account Access Removal](/tags/#account-access-removal) | TTP | | [Download Files Using Telegram](/endpoint/download_files_using_telegram/) | [Ingress Tool Transfer](/tags/#ingress-tool-transfer) | TTP | diff --git a/docs/index.markdown b/docs/index.markdown index 3dc35d1d6b..ed45f74933 100644 --- a/docs/index.markdown +++ b/docs/index.markdown @@ -9,12 +9,12 @@ header: actions: - label: "Download" url: "https://splunkbase.splunk.com/app/3449/" -excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **714** detections for Splunk." +excerpt: "Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **684** detections for Splunk." feature_row: - image_path: /static/feature_detection.png alt: "customizable" title: "Detections" - excerpt: "See all **714** Splunk Analytics built to find evil 😈." + excerpt: "See all **684** Splunk Analytics built to find evil 😈." url: "/detections" btn_class: "btn--primary" btn_label: "Explore"