From ccb8986a40fef7ebb8a3b05b7ebfcd6d8747dfa6 Mon Sep 17 00:00:00 2001 From: Jose Hernandez Date: Mon, 29 Apr 2024 18:07:10 -0400 Subject: [PATCH] adding 4 detections from validation to production mode --- ...packet_lateral_movement_smbexec_commandline_parameters.yml | 4 ++-- ...packet_lateral_movement_wmiexec_commandline_parameters.yml | 4 ++-- .../ssa___serviceprincipalnames_discovery_with_powershell.yml | 4 ++-- .../endpoint/ssa___windows_screen_capture_via_powershell.yml | 4 ++-- ...packet_lateral_movement_smbexec_commandline_parameters.yml | 4 ++-- ...packet_lateral_movement_wmiexec_commandline_parameters.yml | 4 ++-- .../ssa___serviceprincipalnames_discovery_with_powershell.yml | 4 ++-- .../endpoint/ssa___windows_screen_capture_via_powershell.yml | 4 ++-- 8 files changed, 16 insertions(+), 16 deletions(-) diff --git a/dev_ssa/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml b/dev_ssa/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml index f7d0e57edb..4388e8e700 100644 --- a/dev_ssa/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml +++ b/dev_ssa/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml @@ -1,9 +1,9 @@ name: Impacket Lateral Movement smbexec CommandLine Parameters -id: bc7d91c3-8693-4899-808b-1bfc88d58cfa +id: c1238942-2715-41ee-b371-0475da48029c version: 1 date: '2024-01-01' author: Michael Haag, Splunk -status: validation +status: production type: TTP data_source: - Windows Security 4688 diff --git a/dev_ssa/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml b/dev_ssa/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml index b05e14d40d..7de10a1554 100644 --- a/dev_ssa/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml +++ b/dev_ssa/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml @@ -1,9 +1,9 @@ name: Impacket Lateral Movement WMIExec Commandline Parameters -id: d99fb1c3-9934-4fb8-9d00-ab82fc2a01ee +id: 9d07ff50-e968-456e-a3d9-c65c38ed0ab0 version: 1 date: '2024-02-01' author: Michael Haag, Splunk -status: validation +status: production type: TTP data_source: - Windows Security 4688 diff --git a/dev_ssa/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml b/dev_ssa/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml index 277e73d979..c44ef3cd29 100644 --- a/dev_ssa/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml +++ b/dev_ssa/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml @@ -1,9 +1,9 @@ name: ServicePrincipalNames Discovery with PowerShell -id: 54d7a7b1-c60f-431e-992d-b61382ab6b64 +id: 043f07a0-7fd8-40e2-b526-80406fb59abb version: 2 date: '2024-02-01' author: Michael Haag, Splunk -status: validation +status: production type: TTP description: 'The following analytic identifies `powershell.exe` usage, using Script Block Logging EventCode 4104, related to querying the domain for Service Principle diff --git a/dev_ssa/endpoint/ssa___windows_screen_capture_via_powershell.yml b/dev_ssa/endpoint/ssa___windows_screen_capture_via_powershell.yml index 8d02a6b440..51b8730cec 100644 --- a/dev_ssa/endpoint/ssa___windows_screen_capture_via_powershell.yml +++ b/dev_ssa/endpoint/ssa___windows_screen_capture_via_powershell.yml @@ -1,9 +1,9 @@ name: Windows Screen Capture Via Powershell -id: 3b49e58f-04c9-416b-96c9-016ac64e7e5f +id: 678ae7c6-0e63-44db-9881-03202c312f66 version: 1 date: '2024-02-01' author: Teoderick Contreras, Splunk -status: validation +status: production type: TTP data_source: - Powershell 4104 diff --git a/ssa_detections/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml b/ssa_detections/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml index 55da73897a..c750fca38b 100644 --- a/ssa_detections/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml +++ b/ssa_detections/endpoint/ssa___impacket_lateral_movement_smbexec_commandline_parameters.yml @@ -1,10 +1,10 @@ name: Impacket Lateral Movement smbexec CommandLine Parameters -id: bc7d91c3-8693-4899-808b-1bfc88d58cfa +id: c1238942-2715-41ee-b371-0475da48029c version: 1 date: '2024-01-01' author: Michael Haag, Splunk type: TTP -status: validation +status: production description: This analytic focuses on identifying suspicious command-line parameters commonly associated with the use of Impacket wmiexec.py. Impacket is a set of Python classes designed for working with Microsoft network protocols, and it includes several diff --git a/ssa_detections/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml b/ssa_detections/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml index deab77b079..92f0332807 100644 --- a/ssa_detections/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml +++ b/ssa_detections/endpoint/ssa___impacket_lateral_movement_wmiexec_commandline_parameters.yml @@ -1,10 +1,10 @@ name: Impacket Lateral Movement WMIExec Commandline Parameters -id: d99fb1c3-9934-4fb8-9d00-ab82fc2a01ee +id: 9d07ff50-e968-456e-a3d9-c65c38ed0ab0 version: 1 date: '2024-02-01' author: Michael Haag, Splunk type: TTP -status: validation +status: production description: This analytic looks for the presence of suspicious commandline parameters typically present when using Impacket tools. Impacket is a collection of python classes meant to be used with Microsoft network protocols. There are multiple scripts diff --git a/ssa_detections/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml b/ssa_detections/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml index 44c155115c..983a576a5b 100644 --- a/ssa_detections/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml +++ b/ssa_detections/endpoint/ssa___serviceprincipalnames_discovery_with_powershell.yml @@ -1,10 +1,10 @@ name: ServicePrincipalNames Discovery with PowerShell -id: 54d7a7b1-c60f-431e-992d-b61382ab6b64 +id: 043f07a0-7fd8-40e2-b526-80406fb59abb version: 2 date: '2024-02-01' author: Michael Haag, Splunk type: TTP -status: validation +status: production description: 'The following analytic identifies `powershell.exe` usage, using Script Block Logging EventCode 4104, related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver diff --git a/ssa_detections/endpoint/ssa___windows_screen_capture_via_powershell.yml b/ssa_detections/endpoint/ssa___windows_screen_capture_via_powershell.yml index 111ac9a52e..980cf04cfe 100644 --- a/ssa_detections/endpoint/ssa___windows_screen_capture_via_powershell.yml +++ b/ssa_detections/endpoint/ssa___windows_screen_capture_via_powershell.yml @@ -1,10 +1,10 @@ name: Windows Screen Capture Via Powershell -id: 3b49e58f-04c9-416b-96c9-016ac64e7e5f +id: 678ae7c6-0e63-44db-9881-03202c312f66 version: 1 date: '2024-02-01' author: Teoderick Contreras, Splunk type: TTP -status: validation +status: production description: The following analytic identifies a potential PowerShell script that captures screen images on compromised or targeted hosts. This technique was observed in the Winter-Vivern malware, which attempts to capture desktop screens using a