Merge branch 'develop' of github.com:splunk/security_content into develop

This commit is contained in:
tccontre
2021-05-21 12:55:59 +02:00
51 changed files with 1278 additions and 6 deletions
+1
View File
@@ -84,6 +84,7 @@ action.email.useNSSubject = 1
alert.digest_mode = 1
{% if detection.disabled is defined %}
disabled = false
allow_skew = 100%
{% else %}
disabled = true
{% endif %}
+2 -1
View File
@@ -45,6 +45,7 @@ def validate_schema(REPO_PATH, type, objects, verbose):
except yaml.YAMLError as exc:
print(exc)
print("Error reading {0}".format(manifest_file))
errors.append("ERROR: Error reading {0}".format(manifest_file))
error = True
continue
@@ -258,7 +259,7 @@ def validate_tests(REPO_PATH, object):
errors.append('ERROR: orphaned test: {0}, detection file: {1} no longer exists or incorrect detection path under `file`'.format(object['name'], detection_file_path))
else:
errors.append('ERROR: test: {0} does not have a detection `file` associated with detection: {1}'.format(object['name'], test['name']))
test['file']
#test['file']
return errors
def main(REPO_PATH, verbose):
@@ -44,4 +44,7 @@ tags:
- userAgent
- errorCode
- userIdentity.type
risk_object: src_ip
risk_object_type: system
risk_score: 20
security_domain: access
@@ -49,4 +49,7 @@ tags:
- userAgent
- errorCode
- requestParameters.policyName
risk_object: src
risk_object_type: system
risk_score: 20
security_domain: access
@@ -46,4 +46,7 @@ tags:
- userAgent
- errorCode
- requestParameters.policyArn
risk_object: src
risk_object_type: system
risk_score: 20
security_domain: access
@@ -46,4 +46,7 @@ tags:
- userAgent
- errorCode
- requestParameters.groupName
risk_object: src
risk_object_type: system
risk_score: 20
security_domain: identity
@@ -45,4 +45,7 @@ tags:
- userAgent
- errorCode
- requestParameters.groupName
risk_object: src
risk_object_type: system
risk_score: 20
security_domain: identity
@@ -0,0 +1,49 @@
name: Deleting Of Net Users
id: 1c8c6f66-acce-11eb-aafb-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic will detect a suspicious net.exe/net1.exe command-line to
delete a user on a system. This technique may be use by an administrator for legitimate purposes, however this behavior has been used in the wild to impair some
user or deleting adversaries tracks created during its lateral movement additional systems.
During triage, review parallel processes for additional behavior. Identify any other user accounts created before or after.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.parent_process) as parent_process values(Processes.process_id)
as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name="net.exe" OR Processes.process_name="net1.exe" AND
Processes.process="*user*" AND Processes.process="*/delete*" by Processes.process_name
Processes.dest Processes.user Processes.parent_process_name | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `deleting_of_net_users_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed net.exe may be used.
known_false_positives: System administrators or scripts may delete user accounts via this technique. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1531
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_id
- Processes.parent_process
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,50 @@
name: Disable Windows App Hotkeys
id: 1490f224-ad8b-11eb-8c4f-acde48001122
version: 1
date: '2021-05-05'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic detects a suspicious registry modification to disable
Windows hotkey (shortcut keys) for native Windows applications. This technique is commonly
used to disable certain or several Windows applications like `taskmgr.exe` and `cmd.exe`.
This technique is used to impair the analyst in analyzing and removing the attacker implant
in compromised systems.
search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name)
as registry_key_name values(Registry.registry_path) as registry_path min(_time)
as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows
NT\\CurrentVersion\\Image File Execution Options\\*" AND Registry.registry_value_name
= "HotKey Disabled" AND Registry.registry_key_name = "Debugger" by Registry.dest
Registry.user Registry.registry_value_name | `security_content_ctime(lastTime)`
| `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `disable_windows_app_hotkeys_filter`'
how_to_implement: To successfully implement this search, you must be ingesting data
that records registry activity from your hosts to populate the endpoint data model
in the registry node. This is typically populated via endpoint detection-and-response
product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data
used for this search is typically generated via logs that report reads and writes
to the registry.
known_false_positives: unknown
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.registry_value_name
- Registry.dest Registry.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log
@@ -0,0 +1,49 @@
name: Disabling Net User Account
id: c0325326-acd6-11eb-98c2-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic will identify a suspicious command-line that disables a
user account using the `net.exe` utility native to Windows. This technique may used by the adversaries to interrupt
availability of such users to do their malicious act.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.parent_process) as parent_process values(Processes.process_id)
as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name="net.exe" OR Processes.process_name="net1.exe" AND
Processes.process="*user*" AND Processes.process="*/active:no*" by Processes.process_name
Processes.dest Processes.user Processes.parent_process_name | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `disabling_net_user_account_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be
used.
known_false_positives: unknown
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1531
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.parent_process_name
- Processes.process_id
- Processes.parent_process
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,47 @@
name: Download Files Using Telegram
id: 58194e28-ae5e-11eb-8912-acde48001122
version: 1
date: '2021-05-06'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: The following analytic will identify a suspicious download by the Telegram application
on a Windows system. This behavior was identified on a honeypot where the adversary gained access, installed Telegram and followed through with
downloading different network scanners (port, bruteforcer, masscan) to the system and later used to mapped the whole network and further move laterally.
search: '`sysmon` EventCode= 15 process_name = "telegram.exe" TargetFilename = "*:Zone.Identifier"
|stats count min(_time) as firstTime max(_time) as lastTime by Computer EventCode
Image process_id TargetFilename Hash | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `download_files_using_telegram_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name and TargetFilename from your endpoints or Events that
monitor filestream events which is happened when process download something. (EventCode
15) If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon
TA.
known_false_positives: normal download of file in telegram app. (if it was a common
app in network)
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1105
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Computer
- EventCode
- Image
- process_id
- TargetFilename
- Hash
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-sysmon.log
@@ -0,0 +1,48 @@
name: Enumerate Users Local Group Using Telegram
id: fcd74532-ae54-11eb-a5ab-acde48001122
version: 1
date: '2021-05-06'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic will detect a suspicious Telegram process enumerating
all network users in a local group. This technique was seen in a Monero infected honeypot
to mapped all the users on the compromised system. EventCode 4798 is generated when a process enumerates a user's security-enabled local groups on a computer or device.
search: '`wineventlog_security` EventCode=4798 Process_Name = "*\\telegram.exe" |
stats count min(_time) as firstTime max(_time) as lastTime by ComputerName EventCode
Process_Name Process_ID Account_Name Account_Domain Logon_ID Security_ID Message
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `enumerate_users_local_group_using_telegram_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the Task Schedule (Exa. Security Log EventCode 4798) endpoints. Tune and
filter known instances of process like logonUI used in your environment.
known_false_positives: unknown
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4798
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1087
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- ComputerName
- EventCode
- Process_Name
- Process_ID
- Account_Name
- Account_Domain
- Logon_ID
- Security_ID
- Message
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-security.log
@@ -0,0 +1,48 @@
name: Excessive Attempt To Disable Services
id: 8fa2a0f0-acd9-11eb-8994-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic will identify suspicious series of command-line to disable
several services. This technique is seen where the adversary attempts to disable
security app services or other malware services to complete the objective on the compromised system.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name =
"sc.exe" AND Processes.process="*config*" OR Processes.process="*Disabled*" by Processes.process_name
Processes.parent_process_name Processes.dest Processes.user _time span=1m | where
count >=5 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_attempt_to_disable_services_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed sc.exe may be used.
known_false_positives: unknown
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1489
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.process_id
- Processes.process_name
- Processes.parent_process_name
- Processes.dest
- Processes.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,50 @@
name: Excessive Service Stop Attempt
id: ae8d3f4a-acd7-11eb-8846-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies suspicious series of attempt to kill multiple
services on a system using either `net.exe` or `sc.exe`. This technique is use by adversaries
to terminate security services or other related services to continue there objective and
evade detections.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "net.exe"
OR Processes.process_name = "sc.exe" OR Processes.process_name = "net1.exe" AND
Processes.process="*stop*" OR Processes.process="*/delete*" by Processes.process_name
Processes.parent_process_name Processes.dest Processes.user _time span=1m | where
count >=5 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_service_stop_attempt_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed sc.exe may be used.
known_false_positives: unknown
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1489
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.process_id
- Processes.process_name
- Processes.parent_process_name
- Processes.dest
- Processes.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,48 @@
name: Excessive Usage Of Cacls App
id: 0bdf6092-af17-11eb-939a-acde48001122
version: 1
date: '2021-05-07'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: The following analytic identifies excessive usage of `cacls.exe`, `xcacls.exe` or `icacls.exe` application
to change file or folder permission. This behavior is commonly seen where the adversary
attempts to impair some users from deleting or accessing its malware components
or artifact from the compromised system.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id values(Processes.process_name) as process_name
count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes
where Processes.process_name = "cacls.exe" OR Processes.process_name = "icacls.exe"
OR Processes.process_name = "XCACLS.exe" by Processes.parent_process_name Processes.parent_process
Processes.dest Processes.user _time span=1m | where count >=10 | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `excessive_usage_of_cacls_app_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node.
known_false_positives: Administrators or administrative scripts may use this application. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.process_id
- Processes.process_name
- Processes.parent_process_name
- Processes.dest
- Processes.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,47 @@
name: Excessive Usage Of Net App
id: 45e52536-ae42-11eb-b5c6-acde48001122
version: 1
date: '2021-05-06'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies excessive usage of `net.exe` or `net1.exe`
within a bucket of time (1 minute). This behavior was seen in a Monero incident where the adversary attempts
to create many users, delete and disable users as part of its malicious behavior.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "net.exe"
OR Processes.process_name = "net1.exe" by Processes.process_name Processes.parent_process_name
Processes.dest Processes.user _time span=1m | where count >=10 | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `excessive_usage_of_net_app_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed net.exe may be used.
known_false_positives: unknown. Filter as needed. Modify the time span as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1531
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.process_id
- Processes.process_name
- Processes.parent_process_name
- Processes.dest
- Processes.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,47 @@
name: Excessive Usage Of Taskkill
id: fe5bca48-accb-11eb-a67c-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies excessive usage of `taskkill.exe`
application. This application is commonly used by adversaries to evade
detections by killing security product processes or even other processes to evade detection.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "taskkill.exe" by
Processes.parent_process_name Processes.process_name Processes.dest Processes.user
_time span=1m | where count >=10 | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `excessive_usage_of_taskkill_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed taskkill.exe may be used.
known_false_positives: Unknown. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process
- Processes.process_id
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,54 @@
name: Executables Or Script Creation In Suspicious Path
id: a7e3f0f0-ae42-11eb-b245-acde48001122
version: 1
date: '2021-05-06'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic will identify suspicious executable or scripts (known file
extensions) in list of suspicious file path in Windows. This technique is used
by adversaries to evade detection. The suspicious
file path are known paths used in the wild and are not common to have executable or scripts.
search: '|tstats `security_content_summariesonly` values(Filesystem.file_path) as
file_path count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem
where (Filesystem.file_name = *.exe OR Filesystem.file_name = *.dll OR Filesystem.file_name
= *.sys OR Filesystem.file_name = *.com OR Filesystem.file_name = *.vbs OR Filesystem.file_name
= *.vbe OR Filesystem.file_name = *.js OR Filesystem.file_name = *.ps1 OR Filesystem.file_name
= *.bat OR Filesystem.file_name = *.cmd OR Filesystem.file_name = *.pif) AND ( Filesystem.file_path
= *\\windows\\fonts\\* OR Filesystem.file_path = *\\windows\\temp\\* OR Filesystem.file_path
= *\\users\\public\\* OR Filesystem.file_path = *\\windows\\debug\\* OR Filesystem.file_path
= *\\Users\\Administrator\\Music\\* OR Filesystem.file_path = *\\Windows\\servicing\\*
OR Filesystem.file_path = *\\Users\\Default\\* OR Filesystem.file_path = *Recycle.bin*
OR Filesystem.file_path = *\\Windows\\Media\\* OR Filesystem.file_path = *\\Windows\\repair\\*
OR Filesystem.file_path = *\\AppData\\Local\\Temp*) by Filesystem.file_create_time
Filesystem.process_id Filesystem.file_name Filesystem.user | `drop_dm_object_name(Processes)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `executables_or_script_creation_in_suspicious_path_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the Filesystem responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Filesystem` node.
known_false_positives: Administrators may allow creation of script or exe in the paths specified. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1036
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.file_path
- Filesystem.file_create_time
- Filesystem.process_id
- Filesystem.file_name
- Filesystem.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,49 @@
name: Hide User Account From Sign-In Screen
id: 834ba832-ad89-11eb-937d-acde48001122
version: 1
date: '2021-05-05'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies a suspicious registry modification to hide a
user account on the Windows Login screen. This technique was seen in some tradecraft where the adversary will
create a hidden user account with Admin privileges in login screen to avoid noticing
by the user that they already compromise and to persist on that said machine.
search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name)
as registry_key_name values(Registry.registry_path) as registry_path min(_time)
as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Windows
NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\Userlist*" AND Registry.registry_value_name
= "DWORD (0x00000000)" by Registry.dest Registry.user Registry.registry_value_name
| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)`
| `hide_user_account_from_sign_in_screen_filter`'
how_to_implement: To successfully implement this search, you must be ingesting data
that records registry activity from your hosts to populate the endpoint data model
in the registry node. This is typically populated via endpoint detection-and-response
product, such as CarbonBlack or endpoint data sources, such as Sysmon. The data
used for this search is typically generated via logs that report reads and writes
to the registry.
known_false_positives: Unknown. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_key_name
- Registry.registry_path
- Registry.registry_value_name
- Registry.dest Registry.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log
@@ -0,0 +1,48 @@
name: Icacls Deny Command
id: cf8d753e-a8fe-11eb-8f58-acde48001122
version: 1
date: '2021-04-29'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies a potential adversary that changes the security
permission of a specific file or directory. This technique is commonly
seen in APT tradecraft or coinminer scripts. This behavior is meant to evade detection and prevent access to their component files.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe"
OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe"
AND Processes.process = "*/deny*" by Processes.parent_process_name Processes.process_name
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `icacls_deny_command_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used.
known_false_positives: Unknown. It is possible some administrative scripts use ICacls. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process_id
- Processes.process
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,49 @@
name: ICACLS Grant Command
id: b1b1e316-accc-11eb-a9b4-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies potential adversaries that modify the security
permission of a specific file or directory. This technique is commonly
seen in APT tradecraft and coinminer scripts to evade detections and restrict access to their component
files.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "icacls.exe"
OR Processes.process_name = "cacls.exe" OR Processes.process_name = "xcacls.exe"
AND Processes.process = "*/grant*" by Processes.parent_process_name Processes.process_name
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `icacls_grant_command_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used.
known_false_positives: Unknown. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process_id
- Processes.process
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,51 @@
name: Modify ACL permission To Files Or Folder
id: 7e8458cc-acca-11eb-9e3f-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies suspicious modification of ACL permission
to a files or folder to make it available to everyone. This technique may be used by
the adversary to evade ACLs or protected files access. This changes is commonly configured
by the file or directory owner with appropriate permission. This behavior is a good indicator
if this command seen on a machine utilized by an account with no permission to do so.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "cacls.exe"
OR Processes.process_name = "icacls.exe" OR Processes.process_name = "xcacls.exe"
AND (Processes.process = "*/G everyone:*" OR Processes.process = "*/G SYSTEM:*")
by Processes.parent_process_name Processes.process_name Processes.dest Processes.user
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `modify_acl_permission_to_files_or_folder_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used.
known_false_positives: administrators may use this command. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1222
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process
- Processes.process_id
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,46 @@
name: Process Kill Base On File Path
id: 5ffaa42c-acdb-11eb-9ad3-acde48001122
version: 1
date: '2021-05-04'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: The following analytic identifies the use of `wmic.exe` using `delete` to remove a executable path. This is typically ran via a batch file during beginning stages of an adversary setting up for mining on an endpoint.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name =
"wmic.exe" AND Processes.process="*process*" AND Processes.process="*executablepath*"
AND Processes.process="*delete*" by Processes.parent_process_name Processes.process_name
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `process_kill_base_on_file_path_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed wmic.exe may be used.
known_false_positives: Unknown.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1562.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.parent_process_name
- Processes.process_name
- Processes.dest
- Processes.user
- Processes.process
- Processes.process_id
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -12,11 +12,11 @@ description: The following query utilizes Windows Security EventCode 4698, `A sc
technique is common in new trickbot that uses rundll32 to load is trickbot downloader.
The search will return the first time and last time the task was registered, as
well as the `Command` to be executed, `Task Name`, `Author`, `Enabled`, and whether
it is `Hidden` or not.\ schtasks.exe is natively found in `C:\Windows\system32`
and `C:\Windows\syswow64`.\ The following DLL(s) are loaded when schtasks.exe or
it is `Hidden` or not. schtasks.exe is natively found in `C:\Windows\system32`
and `C:\Windows\syswow64`. The following DLL(s) are loaded when schtasks.exe or
TaskService is launched -`taskschd.dll`. If found loaded by another process, it
is possible a scheduled task is being registered within that process context in
memory.\ Upon triage, identify the task scheduled source. Was it schtasks.exe or
memory. Upon triage, identify the task scheduled source. Was it schtasks.exe or
via TaskService? Review the job created and the Command to be executed. Capture
any artifacts on disk and review. Identify any parallel processes within the same
timeframe to identify source.'
@@ -0,0 +1,48 @@
name: Schtasks Run Task On Demand
id: bb37061e-af1f-11eb-a159-acde48001122
version: 1
date: '2021-05-07'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies an on demand run of a Windows Schedule Task through shell
or command-line. This technique has been used by adversaries that force
to run their created Schedule Task as their persistence mechanism or for lateral
movement as part of their malicious attack to the compromised machine.
search: '| tstats `security_content_summariesonly` values(Processes.process) as process
values(Processes.process_id) as process_id count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_name = "schtasks.exe"
Processes.process = "*/run*" by Processes.process_name Processes.parent_process_name
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `schtasks_run_task_on_demand_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the process name, parent process, and command-line executions from your
endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the
Sysmon TA. Tune and filter known instances where renamed schtasks.exe may be used.
known_false_positives: Administrators may use to debug Schedule Task entries. Filter as needed.
references:
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1053
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.process_id
- Processes.process_name
- Processes.parent_process_name
- Processes.dest
- Processes.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,47 @@
name: Suspicious Driver Loaded Path
id: f880acd4-a8f1-11eb-a53b-acde48001122
version: 1
date: '2021-04-29'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic will detect suspicious driver loaded paths. This technique
is commonly used by malicious software like coin miners (xmrig) to register its malicious driver
from notable directories where executable or drivers do not commonly exist.
During triage, validate this driver is for legitimate business use. Review the metadata and certificate information. Unsigned drivers from non-standard paths is not normal, but occurs. In addition, review driver loads into `ntoskrnl.exe` for possible other drivers of interest. Long tail analyze drivers by path (outside of default, and in default) for further review.
search: '`sysmon` EventCode=6 ImageLoaded = "*.sys" NOT (ImageLoaded IN("*\\WINDOWS\\inf","*\\WINDOWS\\System32\\drivers\\*",
"*\\WINDOWS\\System32\\DriverStore\\FileRepository\\*")) | stats min(_time) as
firstTime max(_time) as lastTime count by Computer ImageLoaded Hashes IMPHASH Signature
Signed | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `suspicious_driver_loaded_path_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the driver loaded and Signature from your endpoints. If you are using
Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: Limited false positives will be present. Some applications do load drivers
references:
- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/
- https://redcanary.com/blog/tracking-driver-inventory-to-expose-rootkits/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1543.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Computer
- ImageLoaded
- Hashes
- IMPHASH
- Signature
- Signed
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,54 @@
name: Suspicious Process File Path
id: 9be25988-ad82-11eb-a14f-acde48001122
version: 1
date: '2021-05-05'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: The following analytic will detect a suspicious process running in a file path where
a process is not commonly seen and is most commonly used by malicious softtware. This behavior has been
used by adversaries where they drop and run an exe in a path that is accessible without
admin privileges.
search: '| tstats `security_content_summariesonly` count values(Processes.process_name)
as process_name values(Processes.process) as process min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.process_path = "*\\windows\\fonts\\*"
OR Processes.process_path = "*\\windows\\temp\\*" OR Processes.process_path = "*\\users\\public\\*"
OR Processes.process_path = "*\\windows\\debug\\*" OR Processes.process_path.file_path
= "*\\Users\\Administrator\\Music\\*" OR Processes.process_path.file_path = "*\\Windows\\servicing\\*"
OR Processes.process_path.file_path = "*\\Users\\Default\\*" OR Processes.process_path.file_path
= "*Recycle.bin*" OR Processes.process_path = "*\\Windows\\Media\\*" OR Processes.process_path
= "\\Windows\\repair\\*" OR Processes.process_path = "*\\temp\\*" by Processes.parent_process_name
Processes.parent_process Processes.process_path Processes.dest Processes.user |
`drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `suspicious_process_file_path_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node.
known_false_positives: Administrators may allow execution of specific binaries in non-standard paths. Filter as needed.
references:
- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1543
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.parent_process_name
- Processes.parent_process
- Processes.process_path
- Processes.dest
- Processes.user
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -0,0 +1,44 @@
name: XMRIG Driver Loaded
id: 90080fa6-a8df-11eb-91e4-acde48001122
version: 1
date: '2021-04-29'
author: Teoderick Contreras, Splunk
type: batch
datamodel:
- Endpoint
description: This analytic identifies XMRIG coinminer driver installation on the system.
The XMRIG driver name by default is `WinRing0x64.sys`. This cpu miner is an open source project that is commonly abused
by adversaries to infect and mine bitcoin.
search: '`sysmon` EventCode=6 Signature="Noriyuki MIYAZAKI" OR ImageLoaded= "*\\WinRing0x64.sys"
| stats min(_time) as firstTime max(_time) as lastTime count by Computer ImageLoaded
Hashes IMPHASH Signature Signed | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `xmrig_driver_loaded_filter`'
how_to_implement: To successfully implement this search, you need to be ingesting
logs with the driver loaded and Signature from your endpoints. If you are using
Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
known_false_positives: False positives should be limited.
references:
- https://www.trendmicro.com/vinfo/hk/threat-encyclopedia/malware/trojan.ps1.powtran.a/
tags:
analytic_story:
- XMRig
kill_chain_phases:
- Exploitation
mitre_attack_id:
- T1543.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Computer
- ImageLoaded
- Hashes
- IMPHASH
- Signature
- Signed
security_domain: endpoint
automated_detection_testing: passed
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
@@ -4,7 +4,8 @@ version: 1
date: '2021-04-22'
author: Teoderick Contreras, Splunk
type: batch
datamodel: []
datamodel:
- Network_Traffic
description: This search is to detect potential plain HTTP POST method data exfiltration.
This network traffic is commonly used by trickbot, trojanspy, keylogger or APT adversary
where arguments or commands are sent in plain text to the remote C2 server using
+1 -1
View File
@@ -1,7 +1,7 @@
name: DarkSide Ransomware
id: 507edc74-13d5-4339-878e-b9114ded1f35
version: 1
date: '2020-06-12'
date: '2021-05-12'
author: Bhavin Patel, Splunk
type: batch
description: Leverage searches that allow you to detect and investigate unusual activities
+35
View File
@@ -0,0 +1,35 @@
name: XMRig
id: 06723e6a-6bd8-4817-ace2-5fb8a7b06628
version: 1
date: '2021-05-07'
author: Teoderick Contreras, Rod Soto Splunk
type: batch
description: Leverage searches that allow you to detect and investigate unusual activities
that might relate to the xmrig monero, including looking for file writes associated
with its payload, process command-line, defense evasion (killing services, deleting users, modifying files or folder permission, killing other malware or other coin miner)
and hacking tools including Telegram as mean of command and control (C2) to download other files.
Adversaries may leverage the resources of co-opted systems in order to solve resource intensive problems which may impact system and/or hosted service availability.
One common purpose for Resource Hijacking is to validate transactions of cryptocurrency networks and earn virtual currency.
Adversaries may consume enough system resources to negatively impact and/or cause affected machines to become unresponsive.
(1) Servers and cloud-based
(2) systems are common targets because of the high potential for available resources,
but user endpoint systems may also be compromised and used for Resource Hijacking and cryptocurrency mining.
narrative: XMRig is a high performance, open source, cross platform RandomX, KawPow, CryptoNight and AstroBWT unified CPU/GPU miner.
This monero is seen in the wild on May 2017.
references:
- https://github.com/xmrig/xmrig
- https://www.getmonero.org/resources/user-guides/mine-to-pool.html
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
- https://blog.checkpoint.com/2021/03/11/february-2021s-most-wanted-malware-trickbot-takes-over-following-emotet-shutdown/
tags:
analytic_story: XMRig
category:
- Malware
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection
@@ -0,0 +1,16 @@
name: Deleting Of Net Users Unit Test
tests:
- name: Excessive Deleting Of Users
file: endpoint/deleting_of_net_users.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Disable Windows App Hotkeys Unit Test
tests:
- name: Disable Windows App Hotkeys
file: endpoint/disable_windows_app_hotkeys.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Disabling Net User Account Unit Test
tests:
- name: Disabling Net User Account
file: endpoint/disabling_net_user_account.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,14 @@
name: Download Files Using Telegram Unit Test
tests:
- name: Download Files Using Telegram
file: endpoint/download_files_using_telegram.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Enumerate Users Local Group Using Telegram Unit Test
tests:
- name: Enumerate Users Local Group Using Telegram
file: endpoint/enumerate_users_local_group_using_telegram.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-security.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/minergate/windows-security.log
source: WinEventLog:Security
sourcetype: WinEventLog
@@ -0,0 +1,12 @@
name: Excessive Attempt To Disable Services Unit Test
tests:
- name: Excessive Attempt To Disable Services
file: endpoint/excessive_attempt_to_disable_services.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Excessive Service Stop Attempt Unit Test
tests:
- name: Excessive Service Stop Attempt
file: endpoint/excessive_service_stop_attempt.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Excessive Usage Of Cacls App Unit Test
tests:
- name: Excessive Usage Of Cacls App
file: endpoint/excessive_usage_of_cacls_app.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Excessive Usage Of Net App Unit Test
tests:
- name: Excessive Usage Of Net App
file: endpoint/excessive_usage_of_net_app.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Excessive Usage Of Taskkill Unit Test
tests:
- name: Excessive Usage Of Taskkill
file: endpoint/excessive_usage_of_taskkill.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Executables Or Script Creation In Suspicious Path Unit Test
tests:
- name: Executables Or Script Creation In Suspicious Path
file: endpoint/executables_or_script_creation_in_suspicious_path.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Hide User Account From Sign-In Screen Unit Test
tests:
- name: Hide User Account From Sign-In Screen
file: endpoint/hide_user_account_from_sign_in_screen.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/hotkey_disabled_hidden_user/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Icacls Deny Command Unit Test
tests:
- name: Icacls Deny Command
file: endpoint/icacls_deny_command.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: ICACLS Grant Command Unit Test
tests:
- name: ICACLS Grant Command
file: endpoint/icacls_grant_command.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Modify ACL permission To Files Or Folder Unit Test
tests:
- name: Modify ACL permission To Files Or Folder
file: endpoint/modify_acl_permission_to_files_or_folder.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Process Kill Base On File Path Unit Test
tests:
- name: Process Kill Base On File Path
file: endpoint/process_kill_base_on_file_path.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Schtasks Run Task On Demand Unit Test
tests:
- name: Schtasks Run Task On Demand
file: endpoint/schtasks_run_task_on_demand.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Suspicious Driver Loaded Path Unit Test
tests:
- name: Suspicious Driver Loaded Path
file: endpoint/suspicious_driver_loaded_path.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: Suspicious Process File Path Unit Test
tests:
- name: Suspicious Process File Path
file: endpoint/suspicious_process_file_path.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -0,0 +1,12 @@
name: XMRIG Driver Loaded Unit Test
tests:
- name: XMRIG Driver Loaded
file: endpoint/xmrig_driver_loaded.yml
pass_condition: '| stats count | where count > 0'
earliest_time: '-24h'
latest_time: 'now'
attack_data:
- file_name: windows-sysmon.log
data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/xmrig_miner/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog