Merge branch 'develop' of github.com:splunk/security-content into tf23

This commit is contained in:
Xiao Lin
2021-06-03 16:35:16 -07:00
21 changed files with 327 additions and 22 deletions
@@ -105,13 +105,6 @@ def main(args):
with open('attack_range/attack_range.conf', 'w') as file:
file.write(filedata)
# check if terraform is installed
if which('terraform') is None:
sys.exit(1)
else:
# init terraform
os.system('cd attack_range/terraform/aws && terraform init && cd ../../..')
module = __import__('attack_range')
module.sys.argv = ['attack_range', '--config', 'attack_range/attack_range.conf', 'test', '--test_file', 'security_content/tests/' + test_file_name]
+1 -1
View File
@@ -70,7 +70,7 @@ splunk-sdk==1.6.15
tabulate==0.8.9
termcolor==1.1.0
toml==0.10.2
urllib3==1.26.4
urllib3==1.26.5
virtualenv==20.4.6
wcwidth==0.2.5
wget==3.2
+1 -1
View File
@@ -40,7 +40,7 @@ APPINSPECT_TOKEN=$(curl -s --location --request GET 'https://api.splunk.com/2.0/
sleep 1
# submit a inspection job EXPECTS app on same directory
#REQUEST_ID=$(curl -s --location --request POST 'https://appinspect.splunk.com/v1/app/validate' --header "Authorization: bearer $APPINSPECT_TOKEN" --form 'app_package=@"/home/circleci/DA-ESS-ContentUpdate-latest.tar.gz"' | jq -r '.request_id')
REQUEST_ID=$(curl -s --location --request POST 'https://appinspect.splunk.com/v1/app/validate' --header "Authorization: bearer $APPINSPECT_TOKEN" --form 'app_package=@'$PACKAGE_PATH | jq -r '.request_id')
REQUEST_ID=$(curl -s --location --request POST 'https://appinspect.splunk.com/v1/app/validate' --header "Authorization: bearer $APPINSPECT_TOKEN" --form 'included_tags="cloud"' --form 'app_package=@'$PACKAGE_PATH | jq -r '.request_id')
echo "app inspect request: $REQUEST_ID"
sleep 5
STATUS=$(curl -s --location --request GET https://appinspect.splunk.com/v1/app/validate/status/$REQUEST_ID --header "Authorization: bearer $APPINSPECT_TOKEN" | jq -r '.status')
+1 -1
View File
@@ -84,11 +84,11 @@ action.email.useNSSubject = 1
alert.digest_mode = 1
{% if detection.disabled is defined %}
disabled = false
allow_skew = 100%
{% else %}
disabled = true
{% endif %}
enableSched = 1
allow_skew = 100%
counttype = number of events
relation = greater than
quantity = 0
+1 -1
View File
@@ -20,4 +20,4 @@ six==1.15.0
smmap==3.0.5
toml==0.10.2
u-msgpack-python==2.7.1
urllib3==1.26.4
urllib3==1.26.5
@@ -0,0 +1,49 @@
name: Allow Inbound Traffic By Firewall Rule Registry
id: 0a46537c-be02-11eb-92ca-acde48001122
version: 1
date: '2021-05-26'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic detects a potential suspicious modification of firewall
rule registry allowing inbound traffic in specific port with public profile. This
technique was seen in some attacker want to have a remote access to a machine by
allowing the traffic in firewall rule.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Registry where Registry.registry_path= "*\\System\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\FirewallRules\\*"
Registry.registry_value_name = "*|Action=Allow|*" Registry.registry_value_name =
"*|Dir=In|*" Registry.registry_value_name = "*|Profile=Public|*" Registry.registry_value_name
= "*|LPort=*" by Registry.registry_path Registry.registry_key_name Registry.user
Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`
|`security_content_ctime(lastTime)` | `allow_inbound_traffic_by_firewall_rule_registry_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Registry` node. Also make sure
that this registry was included in your config files ex. sysmon config to be monitored.
known_false_positives: network admin may add/remove/modify public inbound firewall
rule that may cause this rule to be triggered.
references:
- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps
tags:
analytic_story:
- Prohibited Traffic Allowed or Protocol Mismatch
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1021.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_path
- Registry.registry_value_name
- Registry.registry_key_name
- Registry.dest
- Registry.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
@@ -0,0 +1,44 @@
name: Allow Inbound Traffic In Firewall Rule
id: a5d85486-b89c-11eb-8267-acde48001122
version: 1
date: '2021-05-19'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This search is to detect suspicious powershell command to allow inbound
traffic in specific local port with public profile. This technique was seen in some
attacker want to have a remote access to a machine by allowing the traffic in firewall
rule.
search: '`powershell` EventCode=4104 Message = "*firewall*" Message = "*Public*" Message
= "*Inbound*" Message = "*Allow*" Message = "*-LocalPort*" | stats count min(_time)
as firstTime max(_time) as lastTime by EventCode Message ComputerName User | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `allow_inbound_traffic_in_firewall_rule_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the powershell logs from your endpoints. make sure you enable needed
registry to monitor this event.
known_false_positives: administrator may allow inbound traffic in certain network
or machine.
references:
- https://docs.microsoft.com/en-us/powershell/module/netsecurity/new-netfirewallrule?view=windowsserver2019-ps
tags:
analytic_story:
- Prohibited Traffic Allowed or Protocol Mismatch
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1021.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Message
- ComputerName
- User
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
@@ -0,0 +1,46 @@
name: Enable RDP In Other Port Number
id: 99495452-b899-11eb-96dc-acde48001122
version: 1
date: '2021-05-19'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This search is to detect a modification to registry to enable rdp to
a machine with different port number. This technique was seen in some atttacker
tries to do lateral movement and remote access to a compromised machine to gain
control of it.
search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name)
as registry_key_name values(Registry.registry_path) as registry_path min(_time)
as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal
Server\\WinStations\\RDP-Tcp*" Registry.registry_key_name = "PortNumber" by Registry.dest
Registry.user Registry.registry_value_name | `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `enable_rdp_in_other_port_number_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed rundll32.exe may be used.
known_false_positives: unknown
references:
- https://www.mvps.net/docs/how-to-secure-remote-desktop-rdp/
tags:
analytic_story:
- Prohibited Traffic Allowed or Protocol Mismatch
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1021
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_path
- Registry.dest
- Registry.user
- Registry.registry_value_name
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
@@ -2,7 +2,7 @@ name: Excessive Usage of NSLOOKUP App
id: 0a69fdaa-a2b8-11eb-b16d-acde48001122
version: 1
date: '2021-04-21'
author: Teoderick Contreras, Splunk
author: Teoderick Contreras, Stanislav Miskovic, Splunk
type: batch
datamodel:
- Endpoint
@@ -12,12 +12,12 @@ description: this search is to detect potential DNS exfiltration using nslookup
use of nslookup where it tries to use specific record type (TXT, A, AAAA) that are
commonly used by attacker and also the retry parameter which is designed to query
C2 DNS multiple tries.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id values(Processes.parent_process) as parent_process
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name = "nslookup.exe" by Processes.dest Processes.user Processes.process_name
| where count >= 30 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`| `excessive_usage_of_nslookup_app_filter`'
search: '`sysmon` EventCode = 1 process_name = "nslookup.exe" | bucket _time span=15m
| stats count as numNsLookup by Computer, _time | eventstats avg(numNsLookup) as
avgNsLookup, stdev(numNsLookup) as stdNsLookup, count as numSlots by Computer | eval
upperThreshold=(avgNsLookup + stdNsLookup *3) | eval isOutlier=if(avgNsLookup >
20 and avgNsLookup >= upperThreshold, 1, 0) | search isOutlier=1 | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_usage_of_nslookup_app_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
@@ -0,0 +1,45 @@
name: Mailsniper Invoke functions
id: a36972c8-b894-11eb-9f78-acde48001122
version: 1
date: '2021-05-19'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This search is to detect known mailsniper.ps1 functions executed in a
machine. This technique was seen in some attacker to harvest some sensitive e-mail
in a compromised exchange server.
search: '`powershell` EventCode=4104 Message IN ("*Invoke-GlobalO365MailSearch*",
"*Invoke-GlobalMailSearch*", "*Invoke-SelfSearch*", "*Invoke-PasswordSprayOWA*",
"*Invoke-PasswordSprayEWS*","*Invoke-DomainHarvestOWA*", "*Invoke-UsernameHarvestOWA*","*Invoke-OpenInboxFinder*","*Invoke-InjectGEventAPI*","*Invoke-InjectGEvent*","*Invoke-SearchGmail*",
"*Invoke-MonitorCredSniper*", "*Invoke-AddGmailRule*","*Invoke-PasswordSprayEAS*","*Invoke-UsernameHarvestEAS*")
| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Message
ComputerName User | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `mailsniper_invoke_functions_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the powershell logs from your endpoints. make sure you enable needed
registry to monitor this event.
known_false_positives: unknown
references:
- https://www.blackhillsinfosec.com/introducing-mailsniper-a-tool-for-searching-every-users-email-for-sensitive-data/
tags:
analytic_story:
- Data Exfiltration
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1114.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Message
- ComputerName
- User
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
@@ -9,7 +9,7 @@ datamodel:
description: The following analytics identifies a big number of instance of ransomware
notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This
behavior is a good sensor if the ransomware note filename is quite new for security
industry or the ransomware note filename is not in your lookup table list for monitoring.
industry or the ransomware note filename is not in your ransomware lookup table list for monitoring.
search: '`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") |bin _time
span=10s | stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename)
as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer
@@ -0,0 +1,51 @@
name: SecretDumps Offline NTDS Dumping Tool
id: 5672819c-be09-11eb-bbfb-acde48001122
version: 1
date: '2021-05-26'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic detects a potential usage of secretsdump.py tool for dumping
credentials (ntlm hash) from a copy of ntds.dit and SAM.Security,SYSTEM registrry
hive. This technique was seen in some attacker that dump ntlm hashes offline after
having a copy of ntds.dit and SAM/SYSTEM/SECURITY registry hive.
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "python*.exe"
Processes.process = "*.py*" Processes.process = "*-ntds*" (Processes.process = "*-system*"
OR Processes.process = "*-sam*" OR Processes.process = "*-security*" OR Processes.process
= "*-bootkey*") by Processes.process_name Processes.process Processes.parent_process_name
Processes.parent_process Processes.dest Processes.user Processes.process_id Processes.process_guid
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `secretdumps_offline_ntds_dumping_tool_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA.
known_false_positives: unknown
references:
- https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py
tags:
analytic_story:
- Credential Dumping
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1003.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.parent_process_name
- Processes.parent_process
- Processes.dest Processes.user
- Processes.process_id
- Processes.process_guid
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
+9 -1
View File
@@ -287,4 +287,12 @@ Extensions,Name
.WNCRYT,WannaCry
.RYK,Ryuk
.Clop,Clop
.Cllp,Clop
.Cllp,Clop
.JSWORM,JSWorm
.NEMTY_*,Nemty
.NEFILIM,Nefilim
.OFFWHITE,Offwhite
.TELEGRAM,Telegram
.FUSION,Fusion
.MILIHPEN,Milihpen
.GANGBANG,Gangbang
1 Extensions Name
287 .WNCRYT WannaCry
288 .RYK Ryuk
289 .Clop Clop
290 .Cllp Clop
291 .JSWORM JSWorm
292 .NEMTY_* Nemty
293 .NEFILIM Nefilim
294 .OFFWHITE Offwhite
295 .TELEGRAM Telegram
296 .FUSION Fusion
297 .MILIHPEN Milihpen
298 .GANGBANG Gangbang
+1
View File
@@ -1,6 +1,7 @@
default_match: 'false'
description: A list of file extensions that are associated with ransomware
filename: ransomware_extensions.csv
match_type: WILDCARD(Extensions)
min_matches: 1
name: ransomware_extensions_lookup
case_sensitive_match: 'false'
+9 -1
View File
@@ -58,4 +58,12 @@ HELP_DECRYPT_YOUR_FILES.HTML,True
*-READ-FOR-HELLPP.html,True
RyukReadMe.html,True
ClopReadMe.txt,True
README_README.txt,True
README_README.txt,True
JSWORM-DECRYPT.html,True
NEMTY_*-DECRYPT.txt,True
NEFILIM-DECRYPT.txt,True
OFFWHITE-MANUAL.txt,True
TELEGRAM-RECOVER.txt,True
FUSION-README.txt,True
MILIHPEN-INSTRUCT.txt,True
GANGBANG-NOTE.txt,True
1 ransomware_notes status
58 *-READ-FOR-HELLPP.html True
59 RyukReadMe.html True
60 ClopReadMe.txt True
61 README_README.txt True
62 JSWORM-DECRYPT.html True
63 NEMTY_*-DECRYPT.txt True
64 NEFILIM-DECRYPT.txt True
65 OFFWHITE-MANUAL.txt True
66 TELEGRAM-RECOVER.txt True
67 FUSION-README.txt True
68 MILIHPEN-INSTRUCT.txt True
69 GANGBANG-NOTE.txt True
+1 -1
View File
@@ -65,7 +65,7 @@ termcolor==1.1.0
toml==0.10.2
typing==3.7.4.3
tzlocal==2.1
urllib3==1.26.4
urllib3==1.26.5
virtualenv==20.4.6
wcwidth==0.2.5
webencodings==0.5.1
@@ -0,0 +1,12 @@
name: Allow Inbound Traffic By Firewall Rule Registry Unit Test
tests:
- name: Allow Inbound Traffic By Firewall Rule Registry
file: endpoint/allow_inbound_traffic_by_firewall_rule_registry.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Allow Inbound Traffic In Firewall Rule Unit Test
tests:
- name: Allow Inbound Traffic In Firewall Rule
file: endpoint/allow_inbound_traffic_in_firewall_rule.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-powershell.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
source: WinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: WinEventLog
@@ -0,0 +1,12 @@
name: Enable RDP In Other Port Number Unit Test
tests:
- name: Enable RDP In Other Port Number
file: endpoint/enable_rdp_in_other_port_number.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Mailsniper Invoke functions Unit Test
tests:
- name: Mailsniper Invoke functions
file: endpoint/mailsniper_invoke_functions.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-powershell.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-powershell.log
source: WinEventLog:Microsoft-Windows-PowerShell/Operational
sourcetype: WinEventLog
@@ -0,0 +1,12 @@
name: SecretDumps Offline NTDS Dumping Tool Unit Test
tests:
- name: SecretDumps Offline NTDS Dumping Tool
file: endpoint/secretdumps_offline_ntds_dumping_tool.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/honeypots/casper/datasets1/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog