From 20c0196d7f0d18775e983a2aa94897c6cf63f346 Mon Sep 17 00:00:00 2001 From: d1vious Date: Fri, 7 Jan 2022 16:04:21 -0500 Subject: [PATCH 1/9] moving things around --- .../complex/ssa___detect_kerberoasting.yml | 94 ++++++ ...xcessive_number_of_office_files_copied.yml | 64 ++++ ..._first_time_seen_command_line_argument.yml | 89 ++++++ .../ssa___high_file_deletion_frequency.yml | 85 ++++++ ...lbas_applications_in_short_time_period.yml | 95 ++++++ ...ash_observed_at_the_destination_device.yml | 102 +++++++ ...observed_by_an_event_collecting_device.yml | 103 +++++++ ...rare_parent-child_process_relationship.yml | 88 ++++++ .../ssa___unusually_long_command_line.yml | 87 ++++++ ...tolen_credentials_via_mimikatz_modules.yml | 105 +++++++ ...en_credentials_via_powersploit_modules.yml | 100 +++++++ ...ntial_strength_via_dsinternals_modules.yml | 85 ++++++ ...raction_dsinternals_conversion_modules.yml | 95 ++++++ ...dential_extraction_dsinternals_modules.yml | 96 ++++++ ...l_extraction_fgdump_cachedump_s_option.yml | 92 ++++++ ...l_extraction_fgdump_cachedump_v_option.yml | 85 ++++++ ...al_extraction_getaddbaccount_from_dump.yml | 77 +++++ ...ial_extraction_lazagne_command_options.yml | 76 +++++ ...credential_extraction_mimikatz_modules.yml | 81 +++++ ...al_extraction_ms_debuggers_kernel_peek.yml | 86 ++++++ ...ntial_extraction_ms_debuggers_z_option.yml | 82 +++++ ...dential_extraction_powersploit_modules.yml | 82 +++++ .../ssa/deprecated/ssa___detect_pass_hash.yml | 83 ++++++ ...s_user_content_via_powersploit_modules.yml | 83 ++++++ ...count_creation_via_powersploit_modules.yml | 74 +++++ ...enable_disable_via_dsinternals_modules.yml | 77 +++++ ...egal_log_deletion_via_mimikatz_modules.yml | 75 +++++ ...s_and_policies_via_dsinternals_modules.yml | 80 +++++ ...nd_AD_elements_via_powersploit_modules.yml | 81 +++++ ...nd_persistence_via_powersploit_modules.yml | 83 ++++++ ...ivilege_elevation_via_mimikatz_modules.yml | 78 +++++ ...d_process_control_via_mimikatz_modules.yml | 80 +++++ ...rocess_control_via_powersploit_modules.yml | 90 ++++++ ...ction_by_machine_learning_method_-_ssa.yml | 62 ++++ ...en_credentials_via_powersploit_modules.yml | 75 +++++ ..._opportunities_via_powersploit_modules.yml | 91 ++++++ ...roups_policies_via_powersploit_modules.yml | 99 +++++++ ...e_accounts_groups_via_mimikatz_modules.yml | 76 +++++ ...infrastructure_via_powersploit_modules.yml | 89 ++++++ ...puters_domains_via_powersploit_modules.yml | 81 +++++ ...and_use_computers_via_mimikatz_modules.yml | 72 +++++ ...ystem_elements_via_powersploit_modules.yml | 89 ++++++ ...on_and_use_shares_via_mimikatz_modules.yml | 77 +++++ ...and_use_shares_via_powersploit_modules.yml | 81 +++++ ...n_connectivity_via_powersploit_modules.yml | 81 +++++ ...ores_and_services_via_mimikatz_modules.yml | 82 +++++ ...efensive_tools_via_powersploit_modules.yml | 75 +++++ ..._opportunities_via_powersploit_modules.yml | 74 +++++ ...service_hijacking_via_mimikatz_modules.yml | 81 +++++ ...sses_and_services_via_mimikatz_modules.yml | 73 +++++ ...ng_credentials_via_dsinternals_modules.yml | 87 ++++++ ...tting_credentials_via_mimikatz_modules.yml | 77 +++++ ...ng_credentials_via_powersploit_modules.yml | 77 +++++ ...ssa___anomalous_usage_of_archive_tools.yml | 96 ++++++ ...tolen_credentials_via_mimikatz_modules.yml | 126 ++++++++ ...en_credentials_via_powersploit_modules.yml | 121 ++++++++ ...ntial_strength_via_dsinternals_modules.yml | 93 ++++++ .../srs/ssa___attempt_to_delete_services.yml | 106 +++++++ .../srs/ssa___attempt_to_disable_services.yml | 105 +++++++ ...dential_dump_from_registry_via_reg_exe.yml | 96 ++++++ ..._bcdedit_failure_recovery_modification.yml | 99 +++++++ ..._of_fgdump_and_cachedump_with_s_option.yml | 100 +++++++ ..._of_fgdump_and_cachedump_with_v_option.yml | 93 ++++++ ...cative_of_lazagne_command_line_options.yml | 85 ++++++ ...nternals_credential_conversion_modules.yml | 104 +++++++ ...dicative_of_use_of_dsinternals_modules.yml | 106 +++++++ ..._indicative_of_use_of_mimikatz_modules.yml | 90 ++++++ ...dicative_of_use_of_powersploit_modules.yml | 91 ++++++ ...crosoft_debuggers_peek_into_the_kernel.yml | 95 ++++++ ...ft_debuggers_via_z_command_line_option.yml | 91 ++++++ ...present_in_powersploit_and_dsinternals.yml | 86 ++++++ dist/ssa/srs/ssa___delete_a_net_user.yml | 109 +++++++ ...___deny_permission_using_cacls_utility.yml | 92 ++++++ ...detect_dump_lsass_memory_using_comsvcs.yml | 87 ++++++ dist/ssa/srs/ssa___detect_pass_the_hash.yml | 92 ++++++ ...ohibited_applications_spawning_cmd_exe.yml | 103 +++++++ ...ssa___detect_rclone_command-line_usage.yml | 97 ++++++ .../srs/ssa___disable_net_user_account.yml | 104 +++++++ ...___dns_exfiltration_using_nslookup_app.yml | 104 +++++++ dist/ssa/srs/ssa___fsutil_zeroing_file.yml | 97 ++++++ ...__grant_permission_using_cacls_utility.yml | 92 ++++++ ...o_user_content_via_powersploit_modules.yml | 92 ++++++ ...count_creation_via_powersploit_modules.yml | 93 ++++++ ..._deletion_of_logs_via_mimikatz_modules.yml | 83 ++++++ ...ng_of_accounts_via_dsinternals_modules.yml | 85 ++++++ ...s_and_policies_via_dsinternals_modules.yml | 89 ++++++ ...ctory_elements_via_powersploit_modules.yml | 90 ++++++ ...nd_persistence_via_powersploit_modules.yml | 104 +++++++ ...ivilege_elevation_via_mimikatz_modules.yml | 97 ++++++ ...d_process_control_via_mimikatz_modules.yml | 100 +++++++ ...rocess_control_via_powersploit_modules.yml | 110 +++++++ ...fy_acls_permission_of_files_or_folders.yml | 96 ++++++ ...en_credentials_via_powersploit_modules.yml | 96 ++++++ ...counts_and_groups_via_mimikatz_modules.yml | 85 ++++++ ...s_and_policies_via_powersploit_modules.yml | 109 +++++++ ...infrastructure_via_powersploit_modules.yml | 98 ++++++ ...rs_and_domains_via_powersploit_modules.yml | 90 ++++++ ...cess_to_computers_via_mimikatz_modules.yml | 81 +++++ ...ystem_elements_via_powersploit_modules.yml | 98 ++++++ ...sses_and_services_via_mimikatz_modules.yml | 80 +++++ ..._shared_resources_via_mimikatz_modules.yml | 85 ++++++ ...ared_resources_via_powersploit_modules.yml | 90 ++++++ ..._opportunities_via_powersploit_modules.yml | 101 +++++++ ...f_connectivity_via_powersploit_modules.yml | 90 ++++++ ...ores_and_services_via_mimikatz_modules.yml | 91 ++++++ ...efensive_tools_via_powersploit_modules.yml | 83 ++++++ ..._opportunities_via_powersploit_modules.yml | 82 +++++ ...ing_opportunities_via_mimikatz_modules.yml | 90 ++++++ .../srs/ssa___resize_shadowstorage_volume.yml | 105 +++++++ .../ssa___sdelete_application_execution.yml | 110 +++++++ ...ng_credentials_via_dsinternals_modules.yml | 106 +++++++ ...tting_credentials_via_mimikatz_modules.yml | 96 ++++++ ...ng_credentials_via_powersploit_modules.yml | 96 ++++++ ...ocess_running_from_unexpected_location.yml | 280 ++++++++++++++++++ .../ssa___wbadmin_delete_system_backups.yml | 102 +++++++ .../ssa___wevtutil_usage_to_clear_logs.yml | 97 ++++++ .../ssa___wevtutil_usage_to_disable_logs.yml | 93 ++++++ ...dows_curl_upload_to_remote_destination.yml | 115 +++++++ 118 files changed, 10880 insertions(+) create mode 100644 dist/ssa/complex/ssa___detect_kerberoasting.yml create mode 100644 dist/ssa/complex/ssa___excessive_number_of_office_files_copied.yml create mode 100644 dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml create mode 100644 dist/ssa/complex/ssa___high_file_deletion_frequency.yml create mode 100644 dist/ssa/complex/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml create mode 100644 dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml create mode 100644 dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml create mode 100644 dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml create mode 100644 dist/ssa/complex/ssa___unusually_long_command_line.yml create mode 100644 dist/ssa/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_dsinternals_modules.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml create mode 100644 dist/ssa/deprecated/ssa___credential_extraction_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___detect_pass_hash.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml create mode 100644 dist/ssa/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml create mode 100644 dist/ssa/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml create mode 100644 dist/ssa/deprecated/ssa___setting_credentials_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml create mode 100644 dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml create mode 100644 dist/ssa/srs/ssa___attempt_to_delete_services.yml create mode 100644 dist/ssa/srs/ssa___attempt_to_disable_services.yml create mode 100644 dist/ssa/srs/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml create mode 100644 dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml create mode 100644 dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml create mode 100644 dist/ssa/srs/ssa___delete_a_net_user.yml create mode 100644 dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml create mode 100644 dist/ssa/srs/ssa___detect_dump_lsass_memory_using_comsvcs.yml create mode 100644 dist/ssa/srs/ssa___detect_pass_the_hash.yml create mode 100644 dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml create mode 100644 dist/ssa/srs/ssa___detect_rclone_command-line_usage.yml create mode 100644 dist/ssa/srs/ssa___disable_net_user_account.yml create mode 100644 dist/ssa/srs/ssa___dns_exfiltration_using_nslookup_app.yml create mode 100644 dist/ssa/srs/ssa___fsutil_zeroing_file.yml create mode 100644 dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml create mode 100644 dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml create mode 100644 dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___resize_shadowstorage_volume.yml create mode 100644 dist/ssa/srs/ssa___sdelete_application_execution.yml create mode 100644 dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml create mode 100644 dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml create mode 100644 dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml create mode 100644 dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml create mode 100644 dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml create mode 100644 dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml create mode 100644 dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml create mode 100644 dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml diff --git a/dist/ssa/complex/ssa___detect_kerberoasting.yml b/dist/ssa/complex/ssa___detect_kerberoasting.yml new file mode 100644 index 0000000000..0d07185006 --- /dev/null +++ b/dist/ssa/complex/ssa___detect_kerberoasting.yml @@ -0,0 +1,94 @@ +author: Xiao Lin, Splunk +datamodel: +- Certificates +date: '2020-10-21' +description: This search detects a potential kerberoasting attack via service principal + name requests +how_to_implement: The test data is converted from Windows Security Event logs generated + from Attach Range simulation and used in SPL search and extended to SPL2 +id: dabdd6d7-3e10-42be-8711-4e124f7a3850 +known_false_positives: Older systems that support kerberos RC4 by default NetApp may + generate false positives +name: Detect Kerberoasting +product: +- Splunk Behavioral Analytics +references: +- Initial ESCU implementation by Jose Hernandez and Patrick Bareiss +risk_message: Kerberoasting malware is potentially applying stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), + EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, + "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), + ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, + "service_id"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where EventCode="4769" + AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" | first_time_event + input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] + | where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID + | eval start_time=_time, end_time=_time | eval body=create_map(["event_id", event_id, + "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, + "TicketEncryptionType", TicketEncryptionType]), entities = mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | select start_time, end_time, entities, body | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + cis20: + - CIS 8 + - CIS 16 + confidence: 20 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Kerberoasting malware is potentially applying stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1558.003 + - T1558 + nist: + - DE.CM + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - service_name + - _time + - event_code + - ticket_encryption_type + - service_id + - ticket_options + risk_score: 14 + risk_severity: medium + security_domain: endpoint +test: + name: Detect Kerberoasting - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test detection of kerberoasting + file: endpoint/ssa___detect_kerberoasting.yml + name: Detect kerberoasting + pass_condition: '@count_eq(0)' +type: TTP +version: 2 diff --git a/dist/ssa/complex/ssa___excessive_number_of_office_files_copied.yml b/dist/ssa/complex/ssa___excessive_number_of_office_files_copied.yml new file mode 100644 index 0000000000..8a239045f5 --- /dev/null +++ b/dist/ssa/complex/ssa___excessive_number_of_office_files_copied.yml @@ -0,0 +1,64 @@ +author: Patrick Bareiss, Splunk +datamodel: +- Endpoint_Filesystem +date: '2021-12-07' +description: This detection detects a high amount of office file copied. This can + be an indicator for a malicious insider. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Filesytem` node. +id: 3c6594a9-8df6-45a1-9357-d73b62083c63 +known_false_positives: user may copy a lot of office fies from one folder to another +name: Excessive Number of Office Files Copied +product: +- Splunk Behavioral Analytics +references: [] +risk_message: High number of files copied +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", + null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, + "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) + | where "Endpoint_Filesystem" IN(_datamodels) | where action="created" | where like(file_name, + "%.doc%") OR like(file_name, "%.xls%") OR like(file_name, "%.ppt%") | stats count(file_name) + AS count BY dest_user_id, dest_device_id, span(timestamp, 10m) | where count > 20 + | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, + dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' +tags: + analytic_story: [] + confidence: 80 + context: + - Source:Endpoint + - Stage:Exfitration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: High number of files copied + mitre_attack_id: + - T1048.003 + product: + - Splunk Behavioral Analytics + required_fields: + - action + - process + - file_name + - file_path + risk_score: 72 + risk_severity: low + security_domain: endpoint +test: + name: Excessive Number of Office Files Copied Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log + file_name: sysmon.log + source: xmlwineventlog + description: Test for Excessive Number of Office Files Copied + file: endpoint/ssa___excessive_number_of_office_files_copied.yml + name: Excessive Number of Office Files Copied + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml b/dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml new file mode 100644 index 0000000000..5bed7361d2 --- /dev/null +++ b/dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml @@ -0,0 +1,89 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This search looks for command-line arguments that use a `/c` parameter + to execute a command that has not previously been seen. This is an implementation + on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following + analytic identifies first time seen command-line arguments on a single endpoint. + The analytic looks for arguments instantiated by `cmd.exe /c` and the associated + command-line. Adversaries automate or spawn multiple processes using this method, + this analytic may assist with identifying the first time it's been found on this + endpoint.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 +known_false_positives: Legitimate programs use command-line arguments to execute. + Verify the command-line arguments to check what command/program is being executed. + Filtering will be needed. +name: First time seen command line argument +product: +- Splunk Behavioral Analytics +references: [] +risk_message: A process $process_name$ ha been identified in the environment with + a command-line $cmd_line$ not previously seen before on host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), + "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), + cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, + "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, + "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" + */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, "\\PATH"), + /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, + /\d+/, "N"), event_id=ucast(map_get(input_event, "event_id"), "string", null) | + where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* + \/[cC] .*/)=true | select process_name, cmd_line, cmd_line_norm, timestamp, dest_device_id, + dest_user_id | first_time_event input_columns=["cmd_line_norm"] | where first_time_cmd_line_norm + | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, + dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 3 + - CIS 8 + confidence: 60 + context: + - source:endpoint + - stage: Defense Evasion + impact: 50 + kill_chain_phases: + - Command and Control + - Actions on Objectives + message: A process $process_name$ ha been identified in the environment with a command-line + $cmd_line$ not previously seen before on host $dest_device_id$ + mitre_attack_id: + - T1059 + - T1202 + nist: + - PR.PT + - DE.CM + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _time + - dest_device_id + - dest_user_id + - process + - cmd_line + risk_score: 30 + risk_severity: medium + security_domain: endpoint +type: Anomaly +version: 4 diff --git a/dist/ssa/complex/ssa___high_file_deletion_frequency.yml b/dist/ssa/complex/ssa___high_file_deletion_frequency.yml new file mode 100644 index 0000000000..d8d355b0a6 --- /dev/null +++ b/dist/ssa/complex/ssa___high_file_deletion_frequency.yml @@ -0,0 +1,85 @@ +author: Patrick Bareiss, Splunk +datamodel: +- Endpoint_Filesystem +date: '2021-12-07' +description: This detection detects a high amount of file deletions in a short time + for specific file types. This can be an indicator for a malicious insider. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Filesytem` node. +id: b6200efd-13bd-4336-920a-057b25bbcfaf +known_false_positives: user may delete bunch of pictures or files in a folder. +name: High File Deletion Frequency +product: +- Splunk Behavioral Analytics +references: +- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html +- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html +risk_message: High frequency file deletion activity detected on host $Computer$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", + null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, + "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) + | where "Endpoint_Filesystem" IN(_datamodels) | where action="deleted" | where like(file_name, + "%.cmd") OR like(file_name, "%.ini") OR like(file_name, "%.gif") OR like(file_name, + "%.jpg") OR like(file_name, "%.jpeg") OR like(file_name, "%.db") OR like(file_name, + "%.doc%") OR like(file_name, "%.ps1") OR like(file_name, "%.xls%") OR like(file_name, + "%.ppt%") OR like(file_name, "%.bmp") OR like(file_name, "%.zip") OR like(file_name, + "%.rar") OR like(file_name, "%.7z") OR like(file_name, "%.chm") OR like(file_name, + "%.png") OR like(file_name, "%.log") OR like(file_name, "%.vbs") OR like(file_name, + "%.js") | stats count(file_name) AS count BY dest_user_id, dest_device_id, span(timestamp, + 10m) | where count > 20 | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, + dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Clop Ransomware + confidence: 80 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: High frequency file deletion activity detected on host $Computer$ + mitre_attack_id: + - T1485 + observable: + - name: user + role: + - Victim + type: User + - name: Computer + role: + - Victim + type: Endpoint + - name: deleted_files + role: + - Target + type: File Name + product: + - Splunk Behavioral Analytics + required_fields: + - action + - process + - file_name + - file_path + risk_score: 72 + risk_severity: low + security_domain: endpoint +test: + name: High File Deletion Frequency Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log + file_name: sysmon.log + source: xmlwineventlog + description: Test for High File Deletion Frequency + file: endpoint/ssa___high_file_deletion_frequency.yml + name: High File Deletion Frequency + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/complex/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml b/dist/ssa/complex/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml new file mode 100644 index 0000000000..5995bc4c02 --- /dev/null +++ b/dist/ssa/complex/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml @@ -0,0 +1,95 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2020-08-25' +description: Attacker activity may compromise executing several LOLBAS applications + in conjunction to accomplish their objectives. We are looking for more than usual + LOLBAS applications over a window of time, by building profiles per machine. +how_to_implement: Collect endpoint data such as sysmon or 4688 events. +id: 59c0dd70-169c-4900-9a1f-bfcf13302f93 +known_false_positives: 'Some administrative tasks may involve multiple use of LOLBAS + applications in a short period of time. This might trigger false positives at the + beginning when it hasn''t collected yet enough data to construct the baseline. + + ' +name: More than usual number of LOLBAS applications in short time period +product: +- Splunk Behavioral Analytics +references: +- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries +risk_message: A system process $process_name$ with commandline $cmd_line$ spawn iin + short period of time in host $dest_device_id$ +search: ' | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, + "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | where process_name=="regsvcs.exe" OR process_name=="ftp.exe" + OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" + OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" + OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" + OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" + OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" + OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" + OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" + OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" + OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" + OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" + OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" + OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" + OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" + OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" + OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" + OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" + OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" + OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" + OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" + OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR + process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" + OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" + OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" + OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" + OR process_name=="msconfig.exe" | stats count(process_name) as lolbas_counter by + device,span(timestamp, 300s) | eval lolbas_counter=lolbas_counter*1.0 | rename window_end + as timestamp | adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" + window=2419200000L | where label AND quantile>0.99 | eval start_time = window_start, + end_time = timestamp, entities = mvappend(device), body=create_map(["lolbas_counter", + lolbas_counter, "quantile", quantile, "device", device]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 8 + confidence: 50 + context: + - source:endpoint + - stage: Defense Evasion + impact: 50 + kill_chain_phases: + - Exploitation + message: A system process $process_name$ with commandline $cmd_line$ spawn iin short + period of time in host $dest_device_id$ + mitre_attack_id: + - T1059 + - T1053 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: process_name + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - _time + - process_name + risk_score: 25 + risk_severity: medium + security_domain: endpoint +type: Anomaly +version: 2 diff --git a/dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml b/dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml new file mode 100644 index 0000000000..e1415eadc5 --- /dev/null +++ b/dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml @@ -0,0 +1,102 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Authentication +date: '2021-11-30' +description: This detection identifies potential Pass the Token or Pass the Hash credential + stealing. We detect the main side effect of these attacks, which is a transition + from the dominant Kerberos logins to rare NTLM logins for a given user, as reported + by a detination device. +how_to_implement: You must be ingesting Windows Security logs from endpoint devices, + i.e., destinations of interest. Please make sure that event ID 4624 is being logged. +id: 82e76b80-5cdb-4899-9b43-85dbe777b36d +known_false_positives: Environments in which NTLM is used extremely rarely and for + benign purposes (such as a rare use of SMB shares). +name: Potential Pass the Token or Hash Observed at the Destination Device +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1550/002/ +- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ +risk_message: Potential lateral movement and credential stealing via Pass the Token + or Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the destination device $dest_device_id$ +search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", + null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), + dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), + signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), + authentication_method= lower(ucast(map_get(input_event, "authentication_method"), + "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) + + | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") + AND dest_user_id != null AND dest_device_id != null + + | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method + == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) + + | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as + startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as + endNTLMTime by dest_user_id, dest_user, dest_device_id, span(timestamp, 86400s) + + | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - + startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND + (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) + + | eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, + "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["event_id", + event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", + startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", + endNTLMTime]) + + | into write_ssa_detected_events();' +tags: + analytic_story: + - Active Directory Lateral Movement + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Stage:Lateral Movement + impact: 80 + kill_chain_phases: + - Lateral Movement + message: Potential lateral movement and credential stealing via Pass the Token or + Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the destination device $dest_device_id$ + mitre_attack_id: + - T1550 + - T1550.002 + nist: + - PR.PT + - PR.AT + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Other + type: Hostname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - signature_id + - dest_user + - dest_user_id + - dest_device_id + - authentication_method + risk_score: 72 + risk_severity: low + security_domain: endpoint +type: TTP +version: 3 diff --git a/dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml b/dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml new file mode 100644 index 0000000000..74810e4d36 --- /dev/null +++ b/dist/ssa/complex/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml @@ -0,0 +1,103 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Authentication +date: '2021-11-05' +description: This detection identifies potential Pass the Token or Pass the Hash credential + stealing. We detect the main side effect of these attacks, which is a transition + from the dominant Kerberos logins to rare NTLM logins for a given user, as reported + by an event-collecting device (i.e., a specific domain controller or an endpoint + destination). +how_to_implement: You must be ingesting Windows Security logs from devices of interest + - at least from domain controllers. Please make sure that event ID 4624 is being + logged. +id: 1058ba3e-a698-49bc-a1e5-7cedece4ea87 +known_false_positives: Environments in which NTLM is used extremely rarely and for + benign purposes (such as a rare use of SMB shares). +name: Potential Pass the Token or Hash Observed by an Event Collecting Device +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1550/002/ +- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ +risk_message: Potential lateral movement and credential stealing via Pass the Token + or Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the logging device $origin_device_id$ +search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), + "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", + null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", + null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", + null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), + "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") + AND dest_user_id != null AND origin_device_id != null + + | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method + == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) + + | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as + startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as + endNTLMTime by dest_user_id, dest_user, origin_device_id, span(timestamp, 86400s) + + | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - + startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND + (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) + + | eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, + origin_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, + "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", + endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) + + | into write_ssa_detected_events();' +tags: + analytic_story: + - Active Directory Lateral Movement + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 80 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Stage:Lateral Movement + impact: 80 + kill_chain_phases: + - Lateral Movement + message: Potential lateral movement and credential stealing via Pass the Token or + Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the logging device $origin_device_id$ + mitre_attack_id: + - T1550 + - T1550.002 + nist: + - PR.PT + - PR.AT + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: origin_device_id + role: + - Other + type: Hostname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - signature_id + - dest_user + - dest_user_id + - origin_device_id + - authentication_method + risk_score: 64 + risk_severity: low + security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml b/dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml new file mode 100644 index 0000000000..4f0ce19970 --- /dev/null +++ b/dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml @@ -0,0 +1,88 @@ +author: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: An attacker may use LOLBAS tools spawned from vulnerable applications + not typically used by system administrators. This analytic leverages the Splunk + Streaming ML DSP plugin to find rare parent/child relationships. The list of application + has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries +how_to_implement: Collect endpoint data such as sysmon or 4688 events. +id: cf090c78-bcc6-11eb-8529-0242ac130003 +known_false_positives: Some custom tools used by administrators could be used rarely + to launch remotely applications. This might trigger false positives at the beginning + when it has not collected yet enough data to construct the baseline. +name: Rare Parent-Child Process Relationship +product: +- Splunk Behavioral Analytics +references: +- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval parent_process=lower(ucast(map_get(input_event, + "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, + "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, + "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where parent_process_name!=null | select parent_process_name, process_name, cmd_line, + timestamp, dest_device_id, dest_user_id | conditional_anomaly conditional="parent_process_name" + target="process_name" | where (process_name="powershell.exe" OR process_name="regsvcs.exe" + OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" + OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" + OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" + OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" + OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" + OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" + OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" + OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" + OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" + OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" + OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" + OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" + OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" + OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" + OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" + OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" + OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" + OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" + OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" + OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" + OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR + process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" + OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" + OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" + OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") + | eval input = (-1)*log(output) | adaptive_threshold algorithm="gaussian" threshold=0.001 + window=604800000L | where label AND input > mean | eval start_time = timestamp, + end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = + create_map(["process_name", process_name, "parent_process_name", parent_process_name, + "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", + cmd_line]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 8 + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1203 + - T1059 + - T1053 + - T1072 + nist: + - PR.PT + - DE.CM + product: + - Splunk Behavioral Analytics + required_fields: + - process + - process_name + - parent_process_name + - _time + - dest_device_id + - dest_user_id + - cmd_line + risk_severity: low + security_domain: endpoint +type: Anomaly +version: 2 diff --git a/dist/ssa/complex/ssa___unusually_long_command_line.yml b/dist/ssa/complex/ssa___unusually_long_command_line.yml new file mode 100644 index 0000000000..7431805fa7 --- /dev/null +++ b/dist/ssa/complex/ssa___unusually_long_command_line.yml @@ -0,0 +1,87 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-06' +description: Command lines that are extremely long may be indicative of malicious + activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin + to help identify command lines with lengths that are unusual for a given user. This + detection is inspired on Unusually Long Command Line authored by Rico Valdez. +how_to_implement: You must be ingesting sysmon endpoint data that monitors command + lines. +id: 58f43aba-1775-445e-b19c-be2b87d83ae3 +known_false_positives: This detection may flag suspiciously long command lines when + there is not sufficient evidence (samples) for a given process that this detection + is tracking; or when there is high variability in the length of the command line + for the tracked process. Also, some legitimate applications may use long command + lines. Such is the case of Ansible, that encodes Powershell scripts using long base64. + Attackers may use this technique to obfuscate their payloads. +name: Unusually Long Command Line +product: +- Splunk Behavioral Analytics +references: [] +risk_message: A process $process_name$ with a long commandline $cmd_line$ executed + in host $dest_device_id$ +search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval cmd_line=ucast(map_get(input_event, "process"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), + process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line!=null and dest_user_id!=null | eval + cmd_line_norm=replace(cast(cmd_line, "string"), /\s(--?\w+)|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, + /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, + ""))) | select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, + input | adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 + | where label AND quantile>0.99 | first_time_event input_columns=["dest_device_id", + "cmd_line"] | where first_time_dest_device_id_cmd_line | eval start_time = timestamp, + end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", + event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 8 + confidence: 40 + context: + - source:endpoint + - stage: Defense Evasion + impact: 30 + kill_chain_phases: + - Actions on Objectives + message: A process $process_name$ with a long commandline $cmd_line$ executed in + host $dest_device_id$ + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _time + - dest_device_id + - dest_user_id + - process + risk_score: 12 + risk_severity: medium + security_domain: endpoint +test: + name: Unusually Long Command Line - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/unusally_cmd_line/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test unusually long command lines + file: endpoint/ssa___unusually_long_command_line.yml + name: Unusually Long Command Line + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml new file mode 100644 index 0000000000..1ab52f5e28 --- /dev/null +++ b/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml @@ -0,0 +1,105 @@ +name: Applying Stolen Credentials via Mimikatz modules +id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 +version: 2 +date: '2021-11-24' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifites the use of Mimikatz modules attempting + to perform Pass-the-Ticket, Golden or Silver Kerberos ticket attacks and Skeleton + Key attack. This behavior is typically performed within interactive Mimikatz memory + space, however it may be identified on the command-line. A Pass-the-Ticket (ptt) + attack is performed once an adversary has established access to a single endpoint + and retrieved the kerberos ticket to now begin moving laterally using this method. + Typically, it blends in with logon activity as the ticket can be copied to another + system and passed into the current session effectively simulating a logon without + any communication with the Domain Controller. A Golden or Silver ticket attack requires + some setup by the adversary, but once performed it will simulate lateral based authentication + to additional endpoints. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, + /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true + OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) | eval start_time = timestamp, + end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to Mimikatz. +references: +- https://github.com/gentilkiwi/mimikatz +- https://adsecurity.org/?p=1275 +- https://adsecurity.org/?p=1515 +- https://adsecurity.org/?page_id=1821#KERBEROSPTT +- https://attack.mitre.org/software/S0002/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is violating authentication processes by injecting golden + or silver Kerberos tickets or passing stolen authentication tokens. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1055 + - T1068 + - T1078 + - T1098 + - T1134 + - T1543 + - T1547 + - T1548 + - T1554 + - T1556 + - T1558 + - T1558.002 + - T1558.001 + - T1003 + - T1003.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + - cmd_line + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml new file mode 100644 index 0000000000..080e134e90 --- /dev/null +++ b/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml @@ -0,0 +1,100 @@ +name: Applying Stolen Credentials via PowerSploit modules +id: 270b482d-2af2-448f-9923-9cf005f61be4 +version: 2 +date: '2021-11-24' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies commonly used PowerSploit modules that + perform credential access, spoofing of authentication processes, user impersonation + and attempting to manipulate tokens. Specifically, the following modules `Invoke-CredentialInjection`, + `Invoke-TokenManipulation`, `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` + were identfiied as modules used to access credentials. PowerSploit is an archived + project on GitHub, but much of its modules and scripts are still utilized today + by adversaries. This behavior is typically performed within interactive PowerShell + sessions or injected into processes, however it may be identified on the command-line. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true + OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, + /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to PowerSploit. +references: +- https://github.com/PowerShellMafia/PowerSploit +- https://attack.mitre.org/software/S0194/ +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is violating authentication by injecting stolen credentials, + manipulating authentication tokens or impersonating system or user accounts. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1055 + - T1068 + - T1078 + - T1098 + - T1134 + - T1543 + - T1547 + - T1548 + - T1554 + - T1555 + - T1558 + - T1059.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + - cmd_line + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml b/dist/ssa/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml new file mode 100644 index 0000000000..6fb960b256 --- /dev/null +++ b/dist/ssa/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml @@ -0,0 +1,85 @@ +name: Assessment of Credential Strength via DSInternals modules +id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f +version: 2 +date: '2021-11-24' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, + that verifies password strength. Adversaries have utilized this module to determine + password complexity or to identify accounts with weak passwords. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Test-PasswordQuality/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 85 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + impact: 30 + kill_chain_phases: + - Actions on Objectives + message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. + Account attempting this operation is $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1078 + - T1098 + - T1087 + - T1201 + - T1552 + - T1555 + - T1059.001 + - T1059 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + - cmd_line + risk_score: 25 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml b/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml new file mode 100644 index 0000000000..e929f5a744 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml @@ -0,0 +1,95 @@ +name: Credential Extraction indicative of use of DSInternals credential conversion + modules +id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 +version: 2 +date: '2021-11-29' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies modules within DSInternals that are + used for extracting credentials from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, + `ConvertFrom-GPPrefPassword`, `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, + `ConvertTo-LMHash`, `ConvertTo-NTHash` `ConvertTo-OrgIdHash` or `ConvertTo-UnicodePassword`. + Adversaries may use these modules for decrypting or transforming the stored credentials. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, + "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true + OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, + /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true + OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, + /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true + OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, + /(?i)ConvertTo-UnicodePassword/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: DSInternals tool kit is converting stolen credential material to a form + applicable to authentications. Operation is performed on the device $dest_device_id$, + by the account $dest_user_id$ via process $process_name$. + mitre_attack_id: + - T1003 + - T1003.002 + - T1059.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: process_name + type: process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - cmd_line + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_modules.yml b/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_modules.yml new file mode 100644 index 0000000000..131eca2eec --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_modules.yml @@ -0,0 +1,96 @@ +name: Credential Extraction indicative of use of DSInternals modules +id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d +version: 2 +date: '2021-11-29' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies modules of DSInternals being used on + the associated endpoint. Adversaries may use these modules for manipulating data + related to Active Directory and credentials. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, + "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true + OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, + /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true + OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, + /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true + OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true + OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true + OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, + /(?i)Get-SamPasswordPolicy/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: DSInternals tool kit is accessing sensitive credential material such as + KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$ + mitre_attack_id: + - T1003 + - T1003.002 + - T1059.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml b/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml new file mode 100644 index 0000000000..9c28659f43 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml @@ -0,0 +1,92 @@ +name: Credential Extraction indicative of FGDump and CacheDump with s option +id: 312582f2-5e91-42c1-a275-cd67f31373c8 +version: 2 +date: '2021-11-29' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies the use of CacheDump with the `-s` + parameter to dump cached credentials on the associated endpoint. Adversaries use + Cachedump as it is a publicly-available tool that extracts cached password hashes + from a system's registry. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND process_name != null AND parent_process_name != null + AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, + /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true + AND match_regex(cmd_line, /(?i)\-s/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: False positives will be limited as this analytic targets specific + credential dumping process names. Filter as needed. +references: +- https://attack.mitre.org/software/S0119/ +- https://en.kali.tools/all/?tool=182 +- http://foofus.net/goons/fizzgig/fgdump/ +- https://attack.mitre.org/software/S0120/ +tags: + analytic_story: + - Unusual Processes + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is accessing stored credentials via FGDump or CacheDump + tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$. + mitre_attack_id: + - T1003 + - T1003.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml b/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml new file mode 100644 index 0000000000..b1f22d6bb8 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml @@ -0,0 +1,85 @@ +name: Credential Extraction indicative of FGDump and CacheDump with v option +id: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 +version: 2 +date: '2021-11-29' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: The following analytic identifies the use of CacheDump with the `-v` + parameter to dump cached credentials on the associated endpoint. Adversaries use + Cachedump as it is a publicly-available tool that extracts cached password hashes + from a system's registry. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, + /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true + AND match_regex(cmd_line, /(?i)\-v/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: False positives will be limited as this analytic targets specific + credential dumping process names. Filter as needed. +references: [] +tags: + analytic_story: + - Unusual Processes + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is accessing stored credentials via FGDump or CacheDump + tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$ + mitre_attack_id: + - T1003 + - T1003.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 63 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml b/dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml new file mode 100644 index 0000000000..f7d42f0841 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml @@ -0,0 +1,77 @@ +name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and + DSInternals +id: e4f126b5-e6bc-4a5c-b1a8-d07bc6c4a49f +version: 1 +date: '2020-10-18' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: Credential extraction is often an illegal recovery of credential material + from secured authentication resources and repositories. This process may also involve + decryption or other transformations of the stored credential material. PowerSploit + and DSInternals are common exploit APIs offering PowerShell modules for various + exploits of Windows and Active Directory environments. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, + /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\|]+/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: [] +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount + module. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.IP + - PR.AC + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 63 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml b/dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml new file mode 100644 index 0000000000..e18d3f48ad --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml @@ -0,0 +1,76 @@ +name: Credential Extraction indicative of Lazagne command line options +id: 341975fa-4ad0-4f01-9acc-df4f69742db7 +version: 1 +date: '2020-10-18' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: Credential extraction is often an illegal recovery of credential material + from secured authentication resources and repositories. This process may also involve + decryption or other transformations of the stored credential material. LaZagne is + a tool that extracts various kinds of credentials from a local computer, including + account passwords, domain passwords, browser passwords, etc. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, + /(?i)all\s+\-oA\s+\-output/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: [] +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Lazagne malware is extracting/decoding encoded credentials. Operation is + performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ + mitre_attack_id: + - T1003 + - T1555 + nist: + - PR.IP + - PR.AC + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 63 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___credential_extraction_mimikatz_modules.yml new file mode 100644 index 0000000000..719e5d50f1 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_mimikatz_modules.yml @@ -0,0 +1,81 @@ +name: Credential Extraction indicative of use of Mimikatz modules +id: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 +version: 1 +date: '2020-10-21' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: Credential extraction is often an illegal recovery of credential material + from secured authentication resources and repositories. This process may also involve + decryption or other transformations of the stored credential material. Mimikatz + is a collection of tools and modules commonly employed in Windows exploits. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true + OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true + OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true + OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true + OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Credential Dumping + - Unusual Processes + asset_type: Windows + cis20: + - CIS 16 + confidence: 95 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is extracting/decoding encoded credentials from stores + such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 66 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml b/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml new file mode 100644 index 0000000000..b5ad8dfcc2 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml @@ -0,0 +1,86 @@ +name: Credential Extraction native Microsoft debuggers peek into the kernel +id: c20bb8ec-e1b0-4640-b0ef-3a4c54f8c112 +version: 1 +date: '2020-10-18' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: Credential extraction is often an illegal recovery of credential material + from secured authentication resources and repositories. This process may also involve + decryption or other transformations of the stored credential material. Native Microsoft + debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential + material directly from memory and process dumps. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line != null AND parent_process_name != null AND process_name + != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, + /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true + AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: Although unlikely, using debuggers this way may be indicative + of developers analyzing crash dumps of their code. Note, even for developers this + is an unusual way of working on code - debuggers are mostly used to step through + code, not analyze its crash dumps. +references: +- https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29 +tags: + analytic_story: + - Credential Dumping + - Unusual Processes + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is extracting/decoding encoded credentials via Microsoft's + native debugging tools. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.IP + - PR.AC + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - parent_process_name + - _time + - dest_device_id + - dest_user_id + - process + risk_score: 63 + risk_severity: medium + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml b/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml new file mode 100644 index 0000000000..a8c42624e1 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml @@ -0,0 +1,82 @@ +name: Credential Extraction native Microsoft debuggers via z command line option +id: adc51a77-90c9-4358-b43c-f10dd1a27d05 +version: 1 +date: '2020-10-18' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: Credential extraction is often an illegal recovery of credential material + from secured authentication resources and repositories. This process may also involve + decryption or other transformations of the stored credential material. Native Microsoft + debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential + material directly from memory and process dumps. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line != null AND process_name != null AND ( match_regex(process_name, + /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, + /(?i)\-z\s+/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: Although unlikely, using debuggers this way may be indicative + of developers analyzing crash dumps of their code. Note, even for developers this + is an unusual way of working on code - debuggers are mostly used to step through + code, not analyze its crash dumps. +references: [] +tags: + analytic_story: + - Credential Dumping + - Unusual Processes + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is extracting/decoding encoded credentials via Microsoft's + native debugging tools. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _time + - dest_device_id + - dest_user_id + - process + risk_score: 63 + risk_severity: medium + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_powersploit_modules.yml b/dist/ssa/deprecated/ssa___credential_extraction_powersploit_modules.yml new file mode 100644 index 0000000000..04ff3f2af3 --- /dev/null +++ b/dist/ssa/deprecated/ssa___credential_extraction_powersploit_modules.yml @@ -0,0 +1,82 @@ +name: Credential Extraction indicative of use of PowerSploit modules +id: 5f1186a4-e681-446e-851c-dc9574ad28eb +version: 1 +date: '2020-10-21' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: Credential extraction is often an illegal recovery of credential material + from secured authentication resources and repositories. This process may also involve + decryption or other transformations of the stored credential material. PowerSploit + is a collection of Microsoft PowerShell modules commonly employed in exploits. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true + OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true + OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, + /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true + OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, + /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is extracting encoded credentials or spoofing automated + logings. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___detect_pass_hash.yml b/dist/ssa/deprecated/ssa___detect_pass_hash.yml new file mode 100644 index 0000000000..cd076b5e12 --- /dev/null +++ b/dist/ssa/deprecated/ssa___detect_pass_hash.yml @@ -0,0 +1,83 @@ +name: Detect Pass the Hash +id: 7cd8b9fa-6b0c-424f-92a6-9c5287a72f5f +version: 1 +date: '2020-10-21' +author: Xiao Lin, Splunk +type: TTP +datamodel: +- Authentication +description: This search looks for specific authentication events from the Windows + Security Event logs to detect potential attempts using Pass-the-Hash technique. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) + | eval signature_id=map_get(input_event, "signature_id"), authentication_type=map_get(input_event, + "authentication_type"), authentication_method=map_get(input_event, "authentication_method"), + origin_device_domain=map_get(input_event, "origin_device_domain"), dest_user_id=ucast(map_get(input_event, + "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + + | where (authentication_type="3" AND authentication_method="NtLmSsp") OR (authentication_type="9" + AND authentication_method="seclogo") + + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, + dest_user_id), body=create_map(["event_id", event_id, "authentication_type", authentication_type, + "authentication_method", authentication_method]) | into write_ssa_detected_events();' +how_to_implement: The test data is converted from Windows Security Event logs generated + from Attach Range simulation and used in SPL search and extended to SPL2 +known_false_positives: Legitimate logon activity by authorized NTLM systems may be + detected by this search. Please investigate as appropriate. +references: +- Initial ESCU implementation by Bhavin Patel and Patrick Bareiss +tags: + analytic_story: + - Lateral Movement + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 20 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Potential use of the pass the hash/token attacks that spoof authentication. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1550 + - T1550.002 + nist: + - PR.PT + - PR.AT + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - signature_id + - authentication_type + - _time + - authentication_method + - origin_device_domain + - dest_user_id + - dest_device_id + risk_score: 16 + risk_severity: low + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml new file mode 100644 index 0000000000..fda8390475 --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml @@ -0,0 +1,83 @@ +name: Illegal Access To User Content via PowerSploit modules +id: 01fc7d91-eb0c-478e-8633-e4fa4904463a +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that enable illegaly + access user content, such as key logging, audio recording, screenshots, tapping + into http and RDP sessions, etc. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR + match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true + OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, + /(?i)Get-WebConfig/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Exfiltration + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log + impact: 85 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is tapping into user content - microphone, camera, + ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1021 + - T1113 + - T1123 + - T1563 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 85 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml new file mode 100644 index 0000000000..08bb1ad9fc --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml @@ -0,0 +1,74 @@ +name: Illegal Account Creation via PowerSploit modules +id: 20fba62a-fa5b-46cc-b39f-473fa248fee2 +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that create accounts + illegaly. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)New-DomainUser/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Persistence + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is creating illegal domain accounts. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1585 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml b/dist/ssa/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml new file mode 100644 index 0000000000..afdf84bcac --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml @@ -0,0 +1,77 @@ +name: Illegal Enabling or Disabling of Accounts via DSInternals modules +id: 3e0f9962-9989-445f-878c-939443326b63 +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of DSInternals modules that enable or disable + accounts illegaly. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/MichaelGrafnetter/DSInternals +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: DSInternals malware is illegally enabling or disabling accounts. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml new file mode 100644 index 0000000000..24be672979 --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml @@ -0,0 +1,75 @@ +name: Illegal Deletion of Logs via Mimikatz modules +id: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that delete event + logs. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Log Manipulation + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log + impact: 50 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is deleting event logs to cover tracks of malicious activity. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1070 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 50 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml b/dist/ssa/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml new file mode 100644 index 0000000000..85fa7639e5 --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml @@ -0,0 +1,80 @@ +name: Illegal Management of Active Directory Elements and Policies via DSInternals + modules +id: a587ca9f-c138-47b4-ba51-699f319b8cc5 +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of DSInternals modules for illegal management + of Active Directoty elements and policies. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true + OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, + /(?i)Set-LsaPolicyInformation/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/MichaelGrafnetter/DSInternals +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: DSInternals malware is controlling infrastructure by modifying Active Directory + elements, domain controllers, and policies. Operation is performed at the device + $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1098 + - T1207 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml new file mode 100644 index 0000000000..3a54457131 --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml @@ -0,0 +1,81 @@ +name: Illegal Management of Computers and Active Directory Elements via PowerSploit + modules +id: 75760c11-7d48-4968-b828-013b299e8f6d +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that enable illegal + management of computers and Active Directory elements. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR + match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, + /(?i)Set-MasterBootRecord/)=true ) + + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is controlling infrastructure by modifying Active Directory + elements or local Master Boot Records. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1098 + - T1207 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml new file mode 100644 index 0000000000..254a2292a9 --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml @@ -0,0 +1,83 @@ +name: Illegal Privilege Elevation and Persistence via PowerSploit modules +id: 88c10ee9-fe72-4bce-b343-5b129044b991 +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that illegaly + elevate general privileges or ensure persistence, e.g., enable manipulation of registry, + task scheduling, persistent WMI, access to OS objects under desired identities. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true + OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true + OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Malicious PowerShell + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Command And Control + - Stage:Persistence + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is planting attack persistence elements, altering privileges + and access controls. Operation is performed at the device $dest_device_id$, by + the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1053 + - T1134 + - T1548 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml new file mode 100644 index 0000000000..54f6aec7bb --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml @@ -0,0 +1,78 @@ +name: Illegal Privilege Elevation via Mimikatz modules +id: 2f873b1f-6352-4844-b7b9-b419f09a42c7 +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of Mimikatz modules for illegal privilege + elevation. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Privilege Escalation + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is setting highest privileges to malicious entities. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1134 + - T1548 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml new file mode 100644 index 0000000000..c94e7c2c1f --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml @@ -0,0 +1,80 @@ +name: Illegal Service and Process Control via Mimikatz modules +id: aaf3adf1-73e1-4477-b4ee-3771898964f1 +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of Mimikatz modules for illegal control + over services and processes, including the authentication service. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, + /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, + /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true + OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Service Abuse + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is controlling computer's processess and services. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1055 + - T1106 + - T1569 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml new file mode 100644 index 0000000000..835cbc4e6c --- /dev/null +++ b/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml @@ -0,0 +1,90 @@ +name: Illegal Service and Process Control via PowerSploit modules +id: 0e910e5b-309d-4bc3-8af2-0030c02aa353 +version: 1 +date: '2020-11-09' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that enable illegal + control of services and processes, such as installing or spoofing of malicious services, + injecting malicious code in DLLs and EXEs, invoking shell code and WMI commands, + modifying access to service objects, etc. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true + OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, + /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true + OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, + /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true + OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, + /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true + OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, + /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true + ) + + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Service Abuse + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is controlling computer's processess and services. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1055 + - T1106 + - T1569 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml b/dist/ssa/deprecated/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml new file mode 100644 index 0000000000..c1f2707376 --- /dev/null +++ b/dist/ssa/deprecated/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml @@ -0,0 +1,62 @@ +author: Xiao Lin, Splunk +datamodel: [] +date: '2020-08-25' +description: Malicious mails can conduct phishing that induces readers to open attachment, + click links or trigger third party service. This detect uses Natural Language Processing + (NLP) approach to analyze an email message's content (Sender, Subject and Body) + and judge whether it is a phishing email. The detection adopts a deep learning (neural + network) model that employs character level embeddings plus LSTM layers to perform + classification. The model is pre-trained and then published as ONNX format. Current + sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json + User are expected to re-train the model by combining with their own training data + for better accuracy using the provided model file (SMLE notebook). DSP pipeline + then processes the email message and passes it as an event to Apply ML Models function, + which returns the probability of a phishing email. Current implementation assumes + the email is fed to DSP in JSON format contains at least email's sender, subject + and its message body, including reply content, if any. +how_to_implement: Events are fed to DSP contains at least email's sender, subject + and its message body. +id: 4b237388-dfa1-41a6-91d4-4de2d598376f +known_false_positives: Because of imbalance of anomaly data in training, the model + will less likely report false positive. Instead, the model is more prone to false + negative. Current best recall score is ~85% +name: Phishing Email Detection by Machine Learning Method - SSA +product: +- Splunk Behavioral Analytics +references: [] +search: '| from read_ssa_enriched_events() | eval eventLine=concat(ucast(map_get(input_event, + "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " + "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), + _time=map_get(input_event, "_time") | where eventLine IS NOT NULL | eval mapC={" + ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, + ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, + "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, + ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, + "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, + "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, + "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, + "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": + 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": + 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": + 119, "x": 120, "y": 121, "z": 122, "{": 123, "|": 124, "}": 125, "~": 126}, ml_in + = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, + 1)), "float") ) | apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" + path="s3://smle-experiments/models/phishing_email" | eval probability = mvindex(ml_out, + 0) | where probability > 0.5 | eval start_time=_time, end_time=_time, entities="TBD", + body="TBD" | select probability, body, entities, start_time, end_time | into write_ssa_detected_events();' +tags: + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1566 + nist: + - PR.PT + - DE.CM + product: + - Splunk Behavioral Analytics + risk_severity: low + security_domain: mail server +type: Anomaly +version: 1 diff --git a/dist/ssa/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml new file mode 100644 index 0000000000..afcded581a --- /dev/null +++ b/dist/ssa/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml @@ -0,0 +1,75 @@ +name: Probing Access with Stolen Credentials via PowerSploit modules +id: d405af5d-99f1-45af-8dfb-b8f98b764247 +version: 1 +date: '2020-11-04' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of PowerSploit modules that facilitate + access probing with admin credentials as well as probing access to system services. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true + OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Privilege Escalation + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is probing access with stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_user_id + - dest_device_id + risk_score: 60 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml new file mode 100644 index 0000000000..e6238d3e36 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml @@ -0,0 +1,91 @@ +name: Reconnaissance of Access and Persistence Opportunities via PowerSploit modules +id: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 +version: 1 +date: '2020-11-05' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of PowerSploit modules that discover opportunities + for malicious access and persistence. Some examples include access to admin accounts, + weak access control policies, landing paths for dropping malicious software or data + to exfiltrate, registry locations to land autorun parameters, task scheduling opportunities, + as well as services and system files that can be compromised. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true + OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, + /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true + OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, + /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true + OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, + /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true + OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, + /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true + OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, + /(?i)Get-UnquotedService/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for an entry point into the infrastructure, + such as local admin accounts, opportunities to hijack processes, unattended install + files, or modifiable access objects. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1053 + - T1068 + - T1078 + - T1543 + - T1547 + - T1574 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 60 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml new file mode 100644 index 0000000000..e49bc3b415 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml @@ -0,0 +1,99 @@ +name: Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules +id: 63422f8e-766c-468f-8133-2ba6795e263b +version: 1 +date: '2020-11-05' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that discover + accounts, groups and policies that can be accessed or taken over. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true + OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, + /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true + OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, + /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true + OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, + /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true + OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true + OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, + /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true + OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, + /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true + OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true + OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, + /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true + OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true + OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true + OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, + /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true + OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, + /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true + OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, + /(?i)Get-LastLoggedOn/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for and using specific accounts, groups + and policies, such as the last logged on account, a local Net group, etc. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1078 + - T1087 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml new file mode 100644 index 0000000000..96ee3261f0 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml @@ -0,0 +1,76 @@ +name: Reconnaissance and Access to Accounts and Groups via Mimikatz modules +id: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 +version: 1 +date: '2020-11-05' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of Mimikatz modules for discovery of accounts + and groups and access to them. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is searching for and using specific accounts and groups. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1078 + - T1087 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml new file mode 100644 index 0000000000..c711912309 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml @@ -0,0 +1,89 @@ +name: Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit + modules +id: db08ac40-ee14-43e9-9a75-dddd059ef812 +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules for reconnaissance + and access to elements of Active Directory infrastructure, such as domain identifiers, + AD sites and forests, and trust relations. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR + match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true + OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true + OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, + /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true + OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true + OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true + OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, + /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true + OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is seaching for or accessing Active Directory objects + such as domain sites, domain trusts, AD forests, etc. Operation is performed at + the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1199 + - T1482 + - T1590 + - T1591 + - T1595 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml new file mode 100644 index 0000000000..06fa9a94cf --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml @@ -0,0 +1,81 @@ +name: Reconnaissance and Access to Computers and Domains via PowerSploit modules +id: fe1c4c5a-09f3-4b43-8129-560a7f38a08b +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that discover + computers, servers and domains that can be accessed or taken over. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR + match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true + OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true + OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, + /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is seaching for or accessing domain controllers, computers, + file servers, etc. Operation is performed at the device $dest_device_id$, by the + account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1592 + - T1590 + - T1087 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml new file mode 100644 index 0000000000..4de51aecc6 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml @@ -0,0 +1,72 @@ +name: Reconnaissance and Access to Computers via Mimikatz modules +id: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of Mimikatz modules for discovery of computers + and servers and access to them. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)net::ServerInfo/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 50 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is collecting information about computers. Operation is + performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ + mitre_attack_id: + - T1592 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 50 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml new file mode 100644 index 0000000000..4f32e0a43a --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml @@ -0,0 +1,89 @@ +name: Reconnaissance and Access to Operating System Elements via PowerSploit modules +id: c1d33ad9-1727-4f9f-a474-4adbe4fed68a +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that discover + and access operating system elements, such as processes, services, registry locations, + security packages and files. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true + OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, + /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR + match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true + OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true + OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, + /(?i)Get-RegistryMountedDrive/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for and tapping into ongoing processes, + mounted drives or other operating system elements. Operation is performed at the + device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1057 + - T1083 + - T1592.002 + - T1046 + - T1012 + - T1007 + - T1047 + - T1592 + - T1518 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml new file mode 100644 index 0000000000..87194d38a9 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml @@ -0,0 +1,77 @@ +name: Reconnaissance and Access to Shared Resources via Mimikatz modules +id: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of Mimikatz modules for discovery and access + to network shares. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)net::share/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Lateral Movement + - Stage:Collection + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1021 + - T1039 + - T1135 + - T1021.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml new file mode 100644 index 0000000000..ef1f07cc20 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml @@ -0,0 +1,81 @@ +name: Reconnaissance and Access to Shared Resources via PowerSploit modules +id: 6b7ca431-6b1e-4b40-9589-21cb368e369e +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules that discover + and access network and distributed file system shares. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true + OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, + /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true + OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, + /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Lateral Movement + - Stage:Collection + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1021 + - T1039 + - T1135 + - T1021.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml new file mode 100644 index 0000000000..1a656d9570 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml @@ -0,0 +1,81 @@ +name: Reconnaissance of Connectivity via PowerSploit modules +id: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies access to PowerSploit modules for reconnaissance + of connectivity. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true + OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, + /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true + OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, + /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true + OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is performing port scans or searching for various connectivity + details such as DNS data, proxies, or ongoing RDP connections. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1021 + - T1039 + - T1135 + - T1021.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml new file mode 100644 index 0000000000..a6fdc66b33 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml @@ -0,0 +1,82 @@ +name: Reconnaissance of Credential Stores and Services via Mimikatz modules +id: 5facee5b-79e4-47ab-b0e6-c625acc0554f +version: 1 +date: '2020-11-03' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies reconnaissance of credential stores and use + of CryptoAPI services by Mimikatz modules. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, + /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true + OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is searching for and accessing credential stores. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1098 + - T1590.001 + - T1078 + - T1589.001 + - T1590 + - T1068 + - T1589 + - T1590.003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml new file mode 100644 index 0000000000..94908b1186 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml @@ -0,0 +1,75 @@ +name: Reconnaissance of Defensive Tools via PowerSploit modules +id: 24b4e659-63a2-4e7b-89ac-87dd659c7110 +version: 1 +date: '2020-11-05' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of PowerSploit modules for assessment of + presence of defensive tools. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-AVSignature/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 40 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is looking for presence of anti virus software. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1592.002 + - T1595.002 + - T1592 + - T1595 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 40 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml new file mode 100644 index 0000000000..4c2ae2cd99 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml @@ -0,0 +1,74 @@ +name: Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules +id: b9b4492c-2af8-449b-beb4-b1b78d963321 +version: 1 +date: '2020-11-05' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of PowerSploit modules for assessment of + privilege escalation opportunities. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Invoke-PrivescAudit/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is engaging its privilege escalation module. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 60 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml new file mode 100644 index 0000000000..86f058a343 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml @@ -0,0 +1,81 @@ +name: Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules +id: fc5c1cbd-7494-4314-aad2-458d6fd4fada +version: 1 +date: '2020-11-05' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of Mimikatz modules for discovery of process + or service hijacking opportunities via Microsoft Detours compatibility. Microsoft + Detours is an open source library for intercepting, monitoring and instrumenting + binary functions on Microsoft Windows. Detours intercepts Win32 functions by re-writing + the in-memory code for target functions. The Detours package also contains utilities + to attach arbitrary DLLs and data segments called payloads to any Win32 binary. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)misc::detours/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +- https://en.wikipedia.org/wiki/Microsoft_Detours +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is looking for and invoking Microsoft Detours package + that enables spoofing of in-memory code. Operation is performed at the device + $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1543 + - T1055 + - T1574 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml new file mode 100644 index 0000000000..6f4d2c9603 --- /dev/null +++ b/dist/ssa/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml @@ -0,0 +1,73 @@ +name: Reconnaissance and Access to Processes and Services via Mimikatz modules +id: 0243d37c-57c1-4182-bfd1-39b212255fc8 +version: 1 +date: '2020-11-06' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies use of Mimikatz modules for discovery and access + to services and processes. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 50 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is listing processes and services. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1007 + - T1046 + - T1057 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 50 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml b/dist/ssa/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml new file mode 100644 index 0000000000..e8c8223525 --- /dev/null +++ b/dist/ssa/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml @@ -0,0 +1,87 @@ +name: Setting Credentials via DSInternals modules +id: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c +version: 1 +date: '2020-11-03' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies illegal setting of credentials via DSInternals + modules. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, + "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true + OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true + OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, + /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true + OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/MichaelGrafnetter/DSInternals +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Source:Cloud Data + - Stage:Credential Access + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: DSInternals malware is accessing, using or setting Active Directory or + Azure credentials and accounts. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - process + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml b/dist/ssa/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml new file mode 100644 index 0000000000..1499f30134 --- /dev/null +++ b/dist/ssa/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml @@ -0,0 +1,77 @@ +name: Setting Credentials via Mimikatz modules +id: c8b84699-7652-4363-910f-efd1ca82f780 +version: 1 +date: '2020-11-03' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies illegal setting of credentials via Mimikatz + modules. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/gentilkiwi/mimikatz +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is accessing, using or setting account credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 80 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___setting_credentials_via_powersploit_modules.yml b/dist/ssa/deprecated/ssa___setting_credentials_via_powersploit_modules.yml new file mode 100644 index 0000000000..caaf182457 --- /dev/null +++ b/dist/ssa/deprecated/ssa___setting_credentials_via_powersploit_modules.yml @@ -0,0 +1,77 @@ +name: Setting Credentials via PowerSploit modules +id: 07b2a501-f967-4ddc-9f56-2dce46dfce44 +version: 1 +date: '2020-11-03' +author: Stanislav Miskovic, Splunk +type: TTP +datamodel: +- Endpoint_Processes +description: This detection identifies illegal setting of credentials via PowerSploit + modules. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Set-DomainUserPassword/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +known_false_positives: None identified. +references: +- https://github.com/PowerShellMafia/PowerSploit +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is setting passwords on Active Directory accounts. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + type: User + role: + - Actor + - name: dest_device_id + type: Hostname + role: + - Victim + - name: cmd_line + type: processname + role: + - Others + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint diff --git a/dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml b/dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml new file mode 100644 index 0000000000..a0716cc96c --- /dev/null +++ b/dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml @@ -0,0 +1,96 @@ +author: Patrick Bareiss, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-22' +description: The following detection identifies the usage of archive tools from the + command line. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +id: 63614a58-10e2-4c6c-ae81-ea1113681439 +known_false_positives: False positives can be ligitmate usage of archive tools from + the command line. +name: Anomalous usage of Archive Tools +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1560/001/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading + of 7zip. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), + "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), + parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), parent_process=ucast(map_get(input_event, "parent_process"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name + IS NOT NULL AND parent_process_name IS NOT NULL | where like(process_name, "7z%") + OR process_name="WinRAR.exe" OR like(process_name, "winzip%") | where like(parent_process_name, + "%cmd.exe") OR like(parent_process_name, "%powershell.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name", + parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Cobalt Strike + - NOBELIUM Group + confidence: 60 + context: + - Source:Endpoint + - Stage:Collection + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log + impact: 70 + kill_chain_phases: + - Actions on Objective + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading + of 7zip. + mitre_attack_id: + - T1560.001 + - T1560 + observable: + - name: user + role: + - Victim + type: User + - name: dest + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - Processes.process_name + - Processes.process + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + risk_score: 42 + risk_severity: medium + security_domain: endpoint +test: + name: Anomalous usage of Archive Tools Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log + file_name: security.log + source: WinEventLog:Security + description: Test for Anomalous usage of Archive Tools + file: endpoint/ssa___anomalous_usage_of_archive_tools.yml + name: Anomalous usage of Archive Tools + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml new file mode 100644 index 0000000000..c2d7b5f6be --- /dev/null +++ b/dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml @@ -0,0 +1,126 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-24' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifites the use of Mimikatz modules attempting to perform Pass-the-Ticket, + Golden or Silver Kerberos ticket attacks and Skeleton Key attack. This behavior + is typically performed within interactive Mimikatz memory space, however it may + be identified on the command-line. A Pass-the-Ticket (ptt) attack is performed once + an adversary has established access to a single endpoint and retrieved the kerberos + ticket to now begin moving laterally using this method. Typically, it blends in + with logon activity as the ticket can be copied to another system and passed into + the current session effectively simulating a logon without any communication with + the Domain Controller. A Golden or Silver ticket attack requires some setup by the + adversary, but once performed it will simulate lateral based authentication to additional + endpoints.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to Mimikatz. +name: Applying Stolen Credentials via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +- https://adsecurity.org/?p=1275 +- https://adsecurity.org/?p=1515 +- https://adsecurity.org/?page_id=1821#KERBEROSPTT +- https://attack.mitre.org/software/S0002/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash +risk_message: Mimikatz malware is violating authentication processes by injecting + golden or silver Kerberos tickets or passing stolen authentication tokens. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, + /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true + OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) | eval start_time = timestamp, + end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is violating authentication processes by injecting golden + or silver Kerberos tickets or passing stolen authentication tokens. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1055 + - T1068 + - T1078 + - T1098 + - T1134 + - T1543 + - T1547 + - T1548 + - T1554 + - T1556 + - T1558 + - T1558.002 + - T1558.001 + - T1003 + - T1003.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + - cmd_line + risk_score: 90 + risk_severity: high + security_domain: endpoint +test: + name: Applying Stolen Credentials via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test applying stolen credentials detections + file: endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml + name: Applying Stolen Credentials via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml new file mode 100644 index 0000000000..dacb73b8b0 --- /dev/null +++ b/dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml @@ -0,0 +1,121 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-24' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies commonly used PowerSploit modules that perform credential access, + spoofing of authentication processes, user impersonation and attempting to manipulate + tokens. Specifically, the following modules `Invoke-CredentialInjection`, `Invoke-TokenManipulation`, + `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` were identfiied + as modules used to access credentials. PowerSploit is an archived project on GitHub, + but much of its modules and scripts are still utilized today by adversaries. This + behavior is typically performed within interactive PowerShell sessions or injected + into processes, however it may be identified on the command-line.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 270b482d-2af2-448f-9923-9cf005f61be4 +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to PowerSploit. +name: Applying Stolen Credentials via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +- https://attack.mitre.org/software/S0194/ +risk_message: PowerSploit malware is violating authentication by injecting stolen + credentials, manipulating authentication tokens or impersonating system or user + accounts. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true + OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, + /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is violating authentication by injecting stolen credentials, + manipulating authentication tokens or impersonating system or user accounts. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1055 + - T1068 + - T1078 + - T1098 + - T1134 + - T1543 + - T1547 + - T1548 + - T1554 + - T1555 + - T1558 + - T1059.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + - cmd_line + risk_score: 90 + risk_severity: high + security_domain: endpoint +test: + name: Applying Stolen Credentials via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test applying stolen credentials detections + file: endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml + name: Applying Stolen Credentials via PowerSploit + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml new file mode 100644 index 0000000000..81bc5ed977 --- /dev/null +++ b/dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml @@ -0,0 +1,93 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-24' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, that + verifies password strength. Adversaries have utilized this module to determine password + complexity or to identify accounts with weak passwords.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +name: Assessment of Credential Strength via DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +risk_message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. + Account attempting this operation is $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Test-PasswordQuality/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 85 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + impact: 30 + kill_chain_phases: + - Actions on Objectives + message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. + Account attempting this operation is $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1078 + - T1098 + - T1087 + - T1201 + - T1552 + - T1555 + - T1059.001 + - T1059 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + - cmd_line + risk_score: 25 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___attempt_to_delete_services.yml b/dist/ssa/srs/ssa___attempt_to_delete_services.yml new file mode 100644 index 0000000000..043cbf7607 --- /dev/null +++ b/dist/ssa/srs/ssa___attempt_to_delete_services.yml @@ -0,0 +1,106 @@ +author: Teoderick Contreras, splunk +datamodel: +- Endpoint_Processes +date: '2021-11-24' +description: The following analytic identifies Windows Service Control, `sc.exe`, + attempting to delete a service. This is typically identified in parallel with other + instances of service enumeration of attempts to stop a service and then delete it. + Adversaries utilize this technique to terminate security services or other related + services to continue there objective and evade detections. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: a0c8c292-d01a-11eb-aa18-acde48001122 +known_false_positives: It is possible administrative scripts may start/stop/delete + services. Filter as needed. +name: Attempt To Delete Services +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%delete%") AND process_name = "sc.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 8 + - CIS 13 + confidence: 60 + context: + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. + mitre_attack_id: + - T1489 + - T1543 + - T1543.003 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 36 + risk_severity: medium + security_domain: endpoint +test: + name: Attempt To delete Services Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log + file_name: sc_del.log + source: WinEventLog:Security + description: Test for usage of sc.exe to delete a service + file: endpoint/ssa___attempt_to_delete_services.yml + name: Attempt To delete Services + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/srs/ssa___attempt_to_disable_services.yml b/dist/ssa/srs/ssa___attempt_to_disable_services.yml new file mode 100644 index 0000000000..869d013f4b --- /dev/null +++ b/dist/ssa/srs/ssa___attempt_to_disable_services.yml @@ -0,0 +1,105 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-24' +description: The following analytic identifies Windows Service Control, `sc.exe`, + attempting to disable a service. This is typically identified in parallel with other + instances of service enumeration of attempts to stop a service and then disable + it. Adversaries utilize this technique to terminate security services or other related + services to continue there objective and evade detections. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: afb31de4-d023-11eb-98d5-acde48001122 +known_false_positives: It is possible administrative scripts may start/stop/delete + services. Filter as needed. +name: Attempt To Disable Services +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. +search: '| from read_ssa_enriched_events() | eval _datamodels=ucast(map_get(input_event, + "_datamodels"), "collection", []), body={} | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%disabled%") AND like(cmd_line, "%config%") + AND process_name="sc.exe" | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 9 + - CIS 8 + confidence: 60 + context: + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. + mitre_attack_id: + - T1489 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + risk_score: 36 + risk_severity: medium + security_domain: endpoint +test: + name: Attempt To Disable Services Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log + file_name: sc_disable.log + source: WinEventLog:Security + description: Test for usage of sc.exe to disable a service + file: endpoint/ssa___attempt_to_disable_services.yml + name: Attempt To Disable Services + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/srs/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml b/dist/ssa/srs/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml new file mode 100644 index 0000000000..cbc0646e7c --- /dev/null +++ b/dist/ssa/srs/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml @@ -0,0 +1,96 @@ +author: Jose Hernandez, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +description: The following analytic identifies the use of `reg.exe` attempting to + export Windows registry keys that contain hashed credentials. Adversaries will utilize + this technique to capture and perform offline password cracking. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 14038953-e5f2-4daf-acff-5452062baf03 +known_false_positives: None identified. +name: Attempted Credential Dump From Registry via Reg exe +product: +- Splunk Behavioral Analytics +references: +- https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets +risk_message: An attempt to save registry keys storing credentials has been performed + on $dest_device_id$ by $dest_user_id$ via process $process_name$. +search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval process_name=lower(ucast(map_get(input_event, + "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name="cmd.exe" + OR process_name="reg.exe" | where cmd_line != null AND match_regex(cmd_line, /(?i)save\s+/)=true + AND ( match_regex(cmd_line, /(?i)HKLM\\Security/)=true OR match_regex(cmd_line, + /(?i)HKLM\\SAM/)=true OR match_regex(cmd_line, /(?i)HKLM\\System/)=true OR match_regex(cmd_line, + /(?i)HKEY_LOCAL_MACHINE\\Security/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\SAM/)=true + OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\System/)=true ) | eval start_time + = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) + | into write_ssa_detected_events(); ' +tags: + analytic_story: + - Credential Dumping + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: An attempt to save registry keys storing credentials has been performed + on $dest_device_id$ by $dest_user_id$ via process $process_name$. + mitre_attack_id: + - T1003 + - T1003.002 + nist: + - DE.CM + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: process_name + role: + - Child Process + type: process + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _time + - dest_device_id + - dest_user_id + - process + - cmd_line + risk_score: 63 + risk_severity: low + security_domain: endpoint +test: + name: Attempted Credential Dump From Registry via Reg exe - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test credential dumping detections + file: endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml + name: Attempted Credential Dump From Registry via Reg exe + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml b/dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml new file mode 100644 index 0000000000..a27a74f132 --- /dev/null +++ b/dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml @@ -0,0 +1,99 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search looks for flags passed to bcdedit.exe modifications to the + built-in Windows error recovery boot configurations. This is typically used by ransomware + to prevent recovery. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13 +known_false_positives: Administrators may modify the boot configuration. +name: BCDEdit Failure Recovery Modification +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability + to recover the endpoint. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bcdedit.exe" + AND (like (cmd_line, "%recoveryenabled%") AND like (cmd_line, "%no%")) | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - Ryuk Ransomware + - Ransomware + cis20: + - CIS 8 + confidence: 80 + context: + - Source:Endpoint + - Stage:Impact + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability + to recover the endpoint. + mitre_attack_id: + - T1490 + nist: + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: BCDEdit Failure Recovery Modification - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + description: Test detection of BCDEdit Failure Recovery Modification + file: endpoint/ssa___bcdedit_failure_recovery_modification.yml + name: BCDEdit Failure Recovery Modification + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml new file mode 100644 index 0000000000..889f60f282 --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml @@ -0,0 +1,100 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies the use of CacheDump with the `-s` parameter to dump cached + credentials on the associated endpoint. Adversaries use Cachedump as it is a publicly-available + tool that extracts cached password hashes from a system''s registry.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 312582f2-5e91-42c1-a275-cd67f31373c8 +known_false_positives: False positives will be limited as this analytic targets specific + credential dumping process names. Filter as needed. +name: Credential Extraction indicative of FGDump and CacheDump with s option +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/software/S0119/ +- https://en.kali.tools/all/?tool=182 +- http://foofus.net/goons/fizzgig/fgdump/ +- https://attack.mitre.org/software/S0120/ +risk_message: Malicious actor is accessing stored credentials via FGDump or CacheDump + tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$. +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND process_name != null AND parent_process_name != null + AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, + /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true + AND match_regex(cmd_line, /(?i)\-s/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is accessing stored credentials via FGDump or CacheDump + tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$. + mitre_attack_id: + - T1003 + - T1003.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml new file mode 100644 index 0000000000..2cb20aa5bd --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml @@ -0,0 +1,93 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies the use of CacheDump with the `-v` parameter to dump cached + credentials on the associated endpoint. Adversaries use Cachedump as it is a publicly-available + tool that extracts cached password hashes from a system''s registry.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 +known_false_positives: False positives will be limited as this analytic targets specific + credential dumping process names. Filter as needed. +name: Credential Extraction indicative of FGDump and CacheDump with v option +product: +- Splunk Behavioral Analytics +references: [] +risk_message: Malicious actor is accessing stored credentials via FGDump or CacheDump + tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$ +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, + /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true + AND match_regex(cmd_line, /(?i)\-v/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is accessing stored credentials via FGDump or CacheDump + tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$ + mitre_attack_id: + - T1003 + - T1003.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 63 + risk_severity: low + security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml new file mode 100644 index 0000000000..4c2c36d0c0 --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml @@ -0,0 +1,85 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-18' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. LaZagne is a tool that extracts various kinds + of credentials from a local computer, including account passwords, domain passwords, + browser passwords, etc.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 341975fa-4ad0-4f01-9acc-df4f69742db7 +known_false_positives: None identified. +name: Credential Extraction indicative of Lazagne command line options +product: +- Splunk Behavioral Analytics +references: [] +risk_message: Lazagne malware is extracting/decoding encoded credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, + /(?i)all\s+\-oA\s+\-output/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Lazagne malware is extracting/decoding encoded credentials. Operation is + performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ + mitre_attack_id: + - T1003 + - T1555 + nist: + - PR.IP + - PR.AC + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 63 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml new file mode 100644 index 0000000000..8b64d2eba1 --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml @@ -0,0 +1,104 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies modules within DSInternals that are used for extracting credentials + from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, `ConvertFrom-GPPrefPassword`, + `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, + `ConvertTo-LMHash`, `ConvertTo-NTHash` `ConvertTo-OrgIdHash` or `ConvertTo-UnicodePassword`. + Adversaries may use these modules for decrypting or transforming the stored credentials.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +name: Credential Extraction indicative of use of DSInternals credential conversion + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +risk_message: DSInternals tool kit is converting stolen credential material to a form + applicable to authentications. Operation is performed on the device $dest_device_id$, + by the account $dest_user_id$ via process $process_name$. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, + "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true + OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, + /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true + OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, + /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true + OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, + /(?i)ConvertTo-UnicodePassword/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: DSInternals tool kit is converting stolen credential material to a form + applicable to authentications. Operation is performed on the device $dest_device_id$, + by the account $dest_user_id$ via process $process_name$. + mitre_attack_id: + - T1003 + - T1003.002 + - T1059.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: process_name + role: + - Child Process + type: process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - cmd_line + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml new file mode 100644 index 0000000000..f45b2993b6 --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml @@ -0,0 +1,106 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies modules of DSInternals being used on the associated endpoint. + Adversaries may use these modules for manipulating data related to Active Directory + and credentials.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +name: Credential Extraction indicative of use of DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +risk_message: DSInternals tool kit is accessing sensitive credential material such + as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, + "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true + OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, + /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true + OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, + /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true + OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true + OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true + OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, + /(?i)Get-SamPasswordPolicy/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: DSInternals tool kit is accessing sensitive credential material such as + KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$ + mitre_attack_id: + - T1003 + - T1003.002 + - T1059.001 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml new file mode 100644 index 0000000000..152bedd309 --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml @@ -0,0 +1,90 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-21' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. Mimikatz is a collection of tools and modules + commonly employed in Windows exploits.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 +known_false_positives: None identified. +name: Credential Extraction indicative of use of Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is extracting/decoding encoded credentials from stores + such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true + OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true + OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true + OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true + OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + - Unusual Processes + asset_type: Windows + cis20: + - CIS 16 + confidence: 95 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is extracting/decoding encoded credentials from stores + such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 66 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml new file mode 100644 index 0000000000..e6a8ff148f --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml @@ -0,0 +1,91 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-21' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. PowerSploit is a collection of Microsoft PowerShell + modules commonly employed in exploits.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 5f1186a4-e681-446e-851c-dc9574ad28eb +known_false_positives: None identified. +name: Credential Extraction indicative of use of PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is extracting encoded credentials or spoofing automated + logings. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true + OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true + OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, + /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true + OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, + /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is extracting encoded credentials or spoofing automated + logings. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml b/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml new file mode 100644 index 0000000000..82a297f80d --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml @@ -0,0 +1,95 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-18' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, + livekd and windbg, can be leveraged to read credential material directly from memory + and process dumps.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: c20bb8ec-e1b0-4640-b0ef-3a4c54f8c112 +known_false_positives: Although unlikely, using debuggers this way may be indicative + of developers analyzing crash dumps of their code. Note, even for developers this + is an unusual way of working on code - debuggers are mostly used to step through + code, not analyze its crash dumps. +name: Credential Extraction native Microsoft debuggers peek into the kernel +product: +- Splunk Behavioral Analytics +references: +- https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29 +risk_message: Malicious actor is extracting/decoding encoded credentials via Microsoft's + native debugging tools. Operation is performed at the device $dest_device_id$, by + the account $dest_user_id$ via command $cmd_line$ +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line != null AND parent_process_name != null AND process_name + != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, + /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true + AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + - Unusual Processes + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is extracting/decoding encoded credentials via Microsoft's + native debugging tools. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.IP + - PR.AC + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - parent_process_name + - _time + - dest_device_id + - dest_user_id + - process + risk_score: 63 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml b/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml new file mode 100644 index 0000000000..2c56028283 --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml @@ -0,0 +1,91 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-18' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, + livekd and windbg, can be leveraged to read credential material directly from memory + and process dumps.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: adc51a77-90c9-4358-b43c-f10dd1a27d05 +known_false_positives: Although unlikely, using debuggers this way may be indicative + of developers analyzing crash dumps of their code. Note, even for developers this + is an unusual way of working on code - debuggers are mostly used to step through + code, not analyze its crash dumps. +name: Credential Extraction native Microsoft debuggers via z command line option +product: +- Splunk Behavioral Analytics +references: [] +risk_message: Malicious actor is extracting/decoding encoded credentials via Microsoft's + native debugging tools. Operation is performed at the device $dest_device_id$, by + the account $dest_user_id$ via command $cmd_line$ +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line != null AND process_name != null AND ( match_regex(process_name, + /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, + /(?i)\-z\s+/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + - Unusual Processes + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Malicious actor is extracting/decoding encoded credentials via Microsoft's + native debugging tools. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _time + - dest_device_id + - dest_user_id + - process + risk_score: 63 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml b/dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml new file mode 100644 index 0000000000..46f99c3fb1 --- /dev/null +++ b/dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml @@ -0,0 +1,86 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-18' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. PowerSploit and DSInternals are common exploit + APIs offering PowerShell modules for various exploits of Windows and Active Directory + environments.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: e4f126b5-e6bc-4a5c-b1a8-d07bc6c4a49f +known_false_positives: None identified. +name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and + DSInternals +product: +- Splunk Behavioral Analytics +references: [] +risk_message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount + module. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, + /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\|]+/)=true + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount + module. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1003 + nist: + - PR.IP + - PR.AC + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 63 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___delete_a_net_user.yml b/dist/ssa/srs/ssa___delete_a_net_user.yml new file mode 100644 index 0000000000..ba622e4b1c --- /dev/null +++ b/dist/ssa/srs/ssa___delete_a_net_user.yml @@ -0,0 +1,109 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This analytic will detect a suspicious net.exe/net1.exe command-line + to delete a user on a system. This technique may be use by an administrator for + legitimate purposes, however this behavior has been used in the wild to impair some + user or deleting adversaries tracks created during its lateral movement additional + systems. During triage, review parallel processes for additional behavior. Identify + any other user accounts created before or after. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe may be used. +id: 8776d79c-d26e-11eb-9a56-acde48001122 +known_false_positives: System administrators or scripts may delete user accounts via + this technique. Filter as needed. +name: Delete A Net User +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user + account. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" + OR process_name="net.exe") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 4 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log + impact: 70 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user + account. + mitre_attack_id: + - T1531 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 49 + risk_severity: medium + security_domain: endpoint +test: + name: Delete A Net User Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log + file_name: net_user_del.log + source: WinEventLog:Security + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log + file_name: security.log + source: WinEventLog:Security + description: Test for usage of net.exe or net1.exe to delete net user + file: endpoint/ssa___delete_a_net_user.yml + name: Delete A Net User + pass_condition: '@count_gt(0)' +type: Anomaly +version: 3 diff --git a/dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml b/dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml new file mode 100644 index 0000000000..82f434863b --- /dev/null +++ b/dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml @@ -0,0 +1,92 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` + or `xcacls.exe` placing the deny permission on a file or directory. Adversaries + perform this behavior to prevent responders from reviewing or gaining access to + adversary files on disk. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. +id: b76eae28-cd25-11eb-9c92-acde48001122 +known_false_positives: System administrators may use cacls utilities but this is not + a common practice. Filter as needed. +name: Deny Permission using Cacls Utility +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to deny + a permission of a file or directory in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)deny/)=true + AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + cis20: + - CIS 14 + - CIS 16 + confidence: 70 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + impact: 50 + kill_chain_phases: + - Exploitation + message: A cacls process $process_name$ with commandline $cmd_line$ try to deny + a permission of a file or directory in host $dest_device_id$ + mitre_attack_id: + - T1222 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Deny Permission using Cacls Utility Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + file_name: all_icalc.log + source: WinEventLog:Security + description: Test for usage of cacls deny permission to a file(s) or folder(s) + file: endpoint/ssa___deny_permission_using_cacls_utility.yml + name: Deny Permission using Cacls Utility + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/srs/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/dist/ssa/srs/ssa___detect_dump_lsass_memory_using_comsvcs.yml new file mode 100644 index 0000000000..e31f5ae16e --- /dev/null +++ b/dist/ssa/srs/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -0,0 +1,87 @@ +author: Jose Hernandez, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +description: The following analytic identifies credential dumping using comsvcs.dll + with `regsvr32.exe`. This technique is common with adversaries who would like to + dump the memory of lsass.exe and perform offline password cracking. +how_to_implement: You must be ingesting endpoint data that tracks process activity, + including Windows command line logging. You can see how we test this with [Event + Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) + on the [attack_range](https://github.com/splunk/attack_range/blob/develop/ansible/roles/windows_common/tasks/windows-enable-4688-cmd-line-audit.yml). +id: 76bb9e35-f314-4c3d-a385-83c72a13ce4e +known_false_positives: False positives should be limited, filter as needed. +name: Detect Dump LSASS Memory using comsvcs +product: +- Splunk Behavioral Analytics +references: +- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll +risk_message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ + by user $dest_device_user$. +search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_event, + "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), + "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where process_name LIKE "%rundll32.exe%" AND match_regex(process, + /(?i)comsvcs.dll[,\s]+MiniDump/)=true | eval start_time = timestamp, end_time = + timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, + "process_name", process_name, "process", process]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + asset_type: Endpoint + cis20: + - CIS 8 + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ + by user $dest_device_user$. + mitre_attack_id: + - T1003.003 + - T1003 + nist: + - DE.CM + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _tenant + - _time + - dest_device_id + - process + risk_score: 70 + risk_severity: low + security_domain: endpoint +test: + name: Detect Dump LSASS Memory using comsvcs - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test credential dumping detections + file: endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml + name: Detect Dump LSASS Memory using comsvcs + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___detect_pass_the_hash.yml b/dist/ssa/srs/ssa___detect_pass_the_hash.yml new file mode 100644 index 0000000000..54ff68c628 --- /dev/null +++ b/dist/ssa/srs/ssa___detect_pass_the_hash.yml @@ -0,0 +1,92 @@ +author: Xiao Lin, Splunk +datamodel: +- Authentication +date: '2020-10-21' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This search + looks for specific authentication events from the Windows Security Event logs to + detect potential attempts using Pass-the-Hash technique.' +how_to_implement: The test data is converted from Windows Security Event logs generated + from Attach Range simulation and used in SPL search and extended to SPL2 +id: 7cd8b9fa-6b0c-424f-92a6-9c5287a72f5f +known_false_positives: Legitimate logon activity by authorized NTLM systems may be + detected by this search. Please investigate as appropriate. +name: Detect Pass the Hash +product: +- Splunk Behavioral Analytics +references: +- Initial ESCU implementation by Bhavin Patel and Patrick Bareiss +risk_message: Potential use of the pass the hash/token attacks that spoof authentication. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: ' | from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) + | eval signature_id=map_get(input_event, "signature_id"), authentication_type=map_get(input_event, + "authentication_type"), authentication_method=map_get(input_event, "authentication_method"), + origin_device_domain=map_get(input_event, "origin_device_domain"), dest_user_id=ucast(map_get(input_event, + "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + + | where (authentication_type="3" AND authentication_method="NtLmSsp") OR (authentication_type="9" + AND authentication_method="seclogo") + + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, + dest_user_id), body=create_map(["event_id", event_id, "authentication_type", authentication_type, + "authentication_method", authentication_method]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Lateral Movement + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 20 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Potential use of the pass the hash/token attacks that spoof authentication. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1550 + - T1550.002 + nist: + - PR.PT + - PR.AT + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - signature_id + - authentication_type + - _time + - authentication_method + - origin_device_domain + - dest_user_id + - dest_device_id + risk_score: 16 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml b/dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml new file mode 100644 index 0000000000..f369662145 --- /dev/null +++ b/dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml @@ -0,0 +1,103 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-10' +description: The following analytic identifies parent processes, browsers, Windows + terminal applications, Office Products and Java spawning cmd.exe. By its very nature, + many applications spawn cmd.exe natively or built into macros. Much of this will + need to be tuned to further enhance the risk. +how_to_implement: In order to successfully implement this analytic, you will need + endpoint process data from a EDR product or Sysmon. This search has been modified + to process raw sysmon data from attack_range's nxlogs on DSP. +id: c10a18cb-fd80-4ffa-a844-25026e0a0c94 +known_false_positives: There are circumstances where an application may legitimately + execute and interact with the Windows command-line interface. +name: Detect Prohibited Applications Spawning cmd exe +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1059/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event + that warrants investigating. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) + | eval process_name=ucast(map_get(input_event, "process_name"), "string", null), + parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", + null)), cmd_line=lower(ucast(map_get(input_event, "process"),"string", null)), dest_user_id=ucast(map_get(input_event, + "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), + "string", null), event_id=ucast(map_get(input_event,"event_id"), "string", null) + | where process_name="cmd.exe" | rex field=parent_process "(?[^\\\\]+)$" + | where ParentBaseFileName="winword.exe" OR ParentBaseFileName="excel.exe" OR ParentBaseFileName="outlook.exe" + OR ParentBaseFileName="powerpnt.exe" OR ParentBaseFileName="visio.exe" OR ParentBaseFileName="mspub.exe" + OR ParentBaseFileName="acrobat.exe" OR ParentBaseFileName="acrord32.exe" OR ParentBaseFileName="iexplore.exe" + OR ParentBaseFileName="opera.exe" OR ParentBaseFileName="firefox.exe" OR (ParentBaseFileName="java.exe" + AND (cmd_line IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%patch1-Hotfix1a%")))) + OR ParentBaseFileName="powershell.exe" OR (ParentBaseFileName="chrome.exe" AND (cmd_line + IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%chrome-extension%")))) + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, + dest_user_id), body=create_map(["event_id", event_id, "process_name", process_name, + "parent_process_name", parent_process, "cmd_line", cmd_line]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious Command-Line Executions + cis20: + - CIS 8 + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion + impact: 70 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event + that warrants investigating. + mitre_attack_id: + - T1059 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - parent_process_name + - _time + - dest_device_id + - dest_user_id + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Detect Prohibited Applications Spawning cmd exe Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Detect Prohibited Applications Spawning cmd exe + file: endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml + name: Detect Prohibited Applications Spawning cmd exe + pass_condition: '@count_gt(0)' +type: Anomaly +version: 2 diff --git a/dist/ssa/srs/ssa___detect_rclone_command-line_usage.yml b/dist/ssa/srs/ssa___detect_rclone_command-line_usage.yml new file mode 100644 index 0000000000..effffe33fc --- /dev/null +++ b/dist/ssa/srs/ssa___detect_rclone_command-line_usage.yml @@ -0,0 +1,97 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-03' +description: This analytic identifies commonly used command-line arguments used by + `rclone.exe` to initiate a file transfer. Some arguments were negated as they are + specific to the configuration used by adversaries. In particular, an adversary may + list the files or directories of the remote file share using `ls` or `lsd`, which + is not indicative of malicious behavior. During triage, at this stage of a ransomware + event, exfiltration is about to occur or has already. Isolate the endpoint and continue + investigating by review file modifications and parallel processes. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: e8b74268-5454-11ec-a799-acde48001122 +known_false_positives: False positives should be limited as this is restricted to + the Rclone process name. Filter or tune the analytic as needed. +name: Detect RClone Command-Line Usage +product: +- Splunk Behavioral Analytics +references: +- https://redcanary.com/blog/rclone-mega-extortion/ +- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html +- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ +- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a remote + cloud service to move files or folders. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="rclone.exe" + AND (like (cmd_line, "%copy%") OR like (cmd_line, "%mega%")OR like (cmd_line, "%pcloud%") + OR like (cmd_line, "%ftp%") OR like (cmd_line, "%--config%") OR like (cmd_line, + "%--progress%") OR like (cmd_line, "%--no-check-certificate%") OR like (cmd_line, + "%--ignore-existing%") OR like (cmd_line, "%--auto-confirm%") OR like (cmd_line, + "%--transfers%") OR like (cmd_line, "%--multi-thread-streams%")) | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) + | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - DarkSide Ransomware + - Ransomware + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Exfiltration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log + impact: 50 + kill_chain_phases: + - Exfiltration + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a + remote cloud service to move files or folders. + mitre_attack_id: + - T1020 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___disable_net_user_account.yml b/dist/ssa/srs/ssa___disable_net_user_account.yml new file mode 100644 index 0000000000..6e179bef39 --- /dev/null +++ b/dist/ssa/srs/ssa___disable_net_user_account.yml @@ -0,0 +1,104 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This analytic will identify a suspicious command-line that disables a + user account using the native `net.exe` or `net1.exe` utility to Windows. This technique + may used by the adversaries to interrupt availability of accounts and continue the + impact against the organization. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be + used. +id: ba858b08-d26c-11eb-af9b-acde48001122 +known_false_positives: System administrators or automated scripts may disable an account + but not a common practice. Filter as needed. +name: Disable Net User Account +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND like(cmd_line, "%user%") + AND (process_name="net1.exe" OR process_name="net.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 4 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log + impact: 70 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. + mitre_attack_id: + - T1489 + - T1078 + nist: + - PR.AC + - PR.IP + observable: + - name: user + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 49 + risk_severity: medium + security_domain: endpoint +test: + name: Disable Net User Account Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log + file_name: net_user_dis.log + source: WinEventLog:Security + description: Test for usage of net.exe or net1.exe to disable net user + file: endpoint/ssa___disable_net_user_account.yml + name: Disable Net User Account + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/srs/ssa___dns_exfiltration_using_nslookup_app.yml b/dist/ssa/srs/ssa___dns_exfiltration_using_nslookup_app.yml new file mode 100644 index 0000000000..0f154fa153 --- /dev/null +++ b/dist/ssa/srs/ssa___dns_exfiltration_using_nslookup_app.yml @@ -0,0 +1,104 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search is to detect potential DNS exfiltration using nslookup application. + This technique are seen in couple of malware and APT group to exfiltrated collected + data in a infected machine or infected network. This detection is looking for unique + use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are + commonly used by attacker and also the retry parameter which is designed to query + C2 DNS multiple tries. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: 2452e632-9e0d-11eb-34ba-acde48001122 +known_false_positives: It is possible for some legitimate administrative utilities + to use similar cmd_line parameters. Filter as needed. +name: DNS Exfiltration Using Nslookup App +product: +- Splunk Behavioral Analytics +references: +- https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html +- https://www.varonis.com/blog/dns-tunneling/ +- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related + to DNS exfiltration. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="nslookup.exe" + AND (like (cmd_line, "%-querytype=%") OR like (cmd_line, "%-qt=%") OR like (cmd_line, + "%-q=%") OR like (cmd_line, "%-type=%") OR like (cmd_line, "%-retry=%")) | eval + start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious DNS Traffic + - Dynamic DNS + - Command and Control + - Data Exfiltration + automated_detection_testing: passed + confidence: 80 + context: + - Source:Endpoint + - Stage:Exfiltration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related + to DNS exfiltration. + mitre_attack_id: + - T1048 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 72 + risk_severity: low + security_domain: endpoint +test: + name: DNS Exfiltration Using Nslookup App Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + file: endpoint/ssa_dns_exfiltration_using_nslookup_app.yml + name: DNS Exfiltration Using Nslookup App + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___fsutil_zeroing_file.yml b/dist/ssa/srs/ssa___fsutil_zeroing_file.yml new file mode 100644 index 0000000000..0efb8d94cc --- /dev/null +++ b/dist/ssa/srs/ssa___fsutil_zeroing_file.yml @@ -0,0 +1,97 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search is to detect a suspicious fsutil process to zeroing a target + file. This technique was seen in lockbit ransomware where it tries to zero out its + malware path as part of its defense evasion after encrypting the compromised host. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe may be used. +id: f792cdc9-43ee-4429-a3c0-ffce4fed1a85 +known_false_positives: System administrators or scripts may delete user accounts via + this technique. Filter as needed. +name: Fsutil Zeroing File +product: +- Splunk Behavioral Analytics +references: +- https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/ +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file deletion. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" + AND (like (cmd_line, "%setzerodata%")) | eval start_time=timestamp, end_time=timestamp, + entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, + "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", + cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, + "process_path", process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Ransomware + confidence: 90 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: [] + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file + deletion. + mitre_attack_id: + - T1070 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 54 + risk_severity: low + security_domain: endpoint +test: + name: FSUtil Zeroing File - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + description: Test detection of FSUtil Zeroing File + file: endpoint/ssa___fsutil_zeroing_file.yml + name: FSUtil Zeroing File + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml b/dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml new file mode 100644 index 0000000000..70f10dafc1 --- /dev/null +++ b/dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml @@ -0,0 +1,92 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` + or `xcacls.exe` placing the grant permission on a file or directory. Adversaries + perform this behavior to allow components of their files to run, however it allows + responders to review or gaining access to adversary files on disk. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. +id: c6da561a-cd29-11eb-ae65-acde48001122 +known_false_positives: System administrators may use cacls utilities but this is not + a common practice. Filter as needed. +name: Grant Permission Using Cacls Utility +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to grant + user a permission to a file or directory in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)grant/)=true + AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + cis20: + - CIS 14 + - CIS 16 + confidence: 70 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + impact: 50 + kill_chain_phases: + - Exploitation + message: A cacls process $process_name$ with commandline $cmd_line$ try to grant + user a permission to a file or directory in host $dest_device_id$ + mitre_attack_id: + - T1222 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Grant Permission Using Cacls Utility Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + file_name: all_icalc.log + source: WinEventLog:Security + description: Test for usage of cacls grant permission to a file(s) or folder(s) + file: endpoint/ssa___grant_permission_using_cacls_utility.yml + name: Grant Permission Using Cacls Utility + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml new file mode 100644 index 0000000000..341dc81365 --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml @@ -0,0 +1,92 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that enable illegaly access user content, + such as key logging, audio recording, screenshots, tapping into http and RDP sessions, + etc.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 01fc7d91-eb0c-478e-8633-e4fa4904463a +known_false_positives: None identified. +name: Illegal Access To User Content via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is tapping into user content - microphone, camera, + ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR + match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true + OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, + /(?i)Get-WebConfig/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Exfiltration + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log + impact: 85 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is tapping into user content - microphone, camera, + ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1021 + - T1113 + - T1123 + - T1563 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 85 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml new file mode 100644 index 0000000000..97237df015 --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml @@ -0,0 +1,93 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that create accounts illegaly.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 20fba62a-fa5b-46cc-b39f-473fa248fee2 +known_false_positives: None identified. +name: Illegal Account Creation via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is creating illegal domain accounts. Operation is + performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)New-DomainUser/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Persistence + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is creating illegal domain accounts. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1585 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Illegal Account Creation via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test illegal account creation detections + file: endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml + name: Illegal Account Creation via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml new file mode 100644 index 0000000000..aa16051c53 --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml @@ -0,0 +1,83 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that delete event logs.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b +known_false_positives: None identified. +name: Illegal Deletion of Logs via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is deleting event logs to cover tracks of malicious + activity. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Log Manipulation + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log + impact: 50 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is deleting event logs to cover tracks of malicious activity. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1070 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 50 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml new file mode 100644 index 0000000000..4d6a3d0141 --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml @@ -0,0 +1,85 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of DSInternals modules that enable or disable accounts illegaly.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 3e0f9962-9989-445f-878c-939443326b63 +known_false_positives: None identified. +name: Illegal Enabling or Disabling of Accounts via DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +risk_message: DSInternals malware is illegally enabling or disabling accounts. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: DSInternals malware is illegally enabling or disabling accounts. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 80 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml new file mode 100644 index 0000000000..0b45aa84ef --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml @@ -0,0 +1,89 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of DSInternals modules for illegal management of Active Directoty + elements and policies.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: a587ca9f-c138-47b4-ba51-699f319b8cc5 +known_false_positives: None identified. +name: Illegal Management of Active Directory Elements and Policies via DSInternals + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +risk_message: DSInternals malware is controlling infrastructure by modifying Active + Directory elements, domain controllers, and policies. Operation is performed at + the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true + OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, + /(?i)Set-LsaPolicyInformation/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: DSInternals malware is controlling infrastructure by modifying Active Directory + elements, domain controllers, and policies. Operation is performed at the device + $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1098 + - T1207 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml new file mode 100644 index 0000000000..12c1053ff5 --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml @@ -0,0 +1,90 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that enable illegal management of computers + and Active Directory elements.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 75760c11-7d48-4968-b828-013b299e8f6d +known_false_positives: None identified. +name: Illegal Management of Computers and Active Directory Elements via PowerSploit + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is controlling infrastructure by modifying Active + Directory elements or local Master Boot Records. Operation is performed at the device + $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR + match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, + /(?i)Set-MasterBootRecord/)=true ) + + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is controlling infrastructure by modifying Active Directory + elements or local Master Boot Records. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1098 + - T1207 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml new file mode 100644 index 0000000000..6ec2973e83 --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml @@ -0,0 +1,104 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that illegaly elevate general privileges + or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent + WMI, access to OS objects under desired identities.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 88c10ee9-fe72-4bce-b343-5b129044b991 +known_false_positives: None identified. +name: Illegal Privilege Elevation and Persistence via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is planting attack persistence elements, altering + privileges and access controls. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true + OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true + OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Malicious PowerShell + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Command And Control + - Stage:Persistence + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is planting attack persistence elements, altering privileges + and access controls. Operation is performed at the device $dest_device_id$, by + the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1053 + - T1134 + - T1548 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint +test: + name: Illegal Privilege Elevation and Persistence via PowerSploit modules - SSA + Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test privilege elevation and persistence detections + file: endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml + name: Illegal Privilege Elevation and Persistence via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml new file mode 100644 index 0000000000..14b98b6333 --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml @@ -0,0 +1,97 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for illegal privilege elevation.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 2f873b1f-6352-4844-b7b9-b419f09a42c7 +known_false_positives: None identified. +name: Illegal Privilege Elevation via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is setting highest privileges to malicious entities. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Privilege Escalation + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is setting highest privileges to malicious entities. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1134 + - T1548 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint +test: + name: Illegal Privilege Elevation via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test illegal privilege elevation detections + file: endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml + name: Illegal Privilege Elevation via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml new file mode 100644 index 0000000000..65e6678eaa --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml @@ -0,0 +1,100 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for illegal control over services and processes, + including the authentication service.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: aaf3adf1-73e1-4477-b4ee-3771898964f1 +known_false_positives: None identified. +name: Illegal Service and Process Control via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is controlling computer's processess and services. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, + /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, + /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true + OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Service Abuse + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Command And Control + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is controlling computer's processess and services. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1055 + - T1106 + - T1569 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint +test: + name: Illegal Service and Process Control via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test illegal service and process control detections + file: endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml + name: Illegal Service and Process Control via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml new file mode 100644 index 0000000000..6766a7231c --- /dev/null +++ b/dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml @@ -0,0 +1,110 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that enable illegal control of services + and processes, such as installing or spoofing of malicious services, injecting malicious + code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to + service objects, etc.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 0e910e5b-309d-4bc3-8af2-0030c02aa353 +known_false_positives: None identified. +name: Illegal Service and Process Control via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is controlling computer's processess and services. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true + OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, + /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true + OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, + /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true + OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, + /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true + OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, + /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true + ) + + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Service Abuse + - Malicious PowerShell + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is controlling computer's processess and services. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1055 + - T1106 + - T1569 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint +test: + name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test illegal service and process control detections + file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml + name: Illegal Service and Process Control via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml b/dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml new file mode 100644 index 0000000000..ae2e490edf --- /dev/null +++ b/dist/ssa/srs/ssa___modify_acls_permission_of_files_or_folders.yml @@ -0,0 +1,96 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This analytic identifies suspicious modification of ACL permission to + a files or folder to make it available to everyone or to a specific user. This technique + may be used by the adversary to evade ACLs or protected files access. This changes + is commonly configured by the file or directory owner with appropriate permission. + This behavior raises suspicion if this command is seen on an endpoint utilized by + an account with no permission to do so. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. +id: 9ae9a48a-cdbe-11eb-875a-acde48001122 +known_false_positives: System administrators may use this windows utility. filter + is needed. +name: Modify ACLs Permission Of Files Or Folders +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to modify + a permission of a file or directory in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line IS NOT NULL AND like(cmd_line, "%/G%") AND (match_regex(cmd_line, + /(?i)everyone:/)=true OR match_regex(cmd_line, /(?i)SYSTEM:/)=true) AND (process_name="cacls.exe" + OR process_name="xcacls.exe" OR process_name="icacls.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + cis20: + - CIS 8 + - CIS 13 + confidence: 70 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + impact: 50 + kill_chain_phases: + - Exploitation + message: A cacls process $process_name$ with commandline $cmd_line$ try to modify + a permission of a file or directory in host $dest_device_id$ + mitre_attack_id: + - T1222 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Modify ACLs Permission Of Files Or Folders Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + file_name: all_icalc.log + source: WinEventLog:Security + description: Test for modifying permission of a file(s) or folder(s) using cacls + utility. + file: endpoint/ssa___modify_acls_permission_of_files_or_folders.yml + name: Modify ACLs Permission Of Files Or Folders + pass_condition: '@count_gt(0)' +type: Anomaly +version: 2 diff --git a/dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml new file mode 100644 index 0000000000..a7053b9879 --- /dev/null +++ b/dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml @@ -0,0 +1,96 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-04' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules that facilitate access probing with admin + credentials as well as probing access to system services.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: d405af5d-99f1-45af-8dfb-b8f98b764247 +known_false_positives: None identified. +name: Probing Access with Stolen Credentials via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is probing access with stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true + OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Privilege Escalation + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is probing access with stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_user_id + - dest_device_id + risk_score: 60 + risk_severity: low + security_domain: endpoint +test: + name: Probing Access with Stolen Credentials via PowerSploit modules - SSA Unit + test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test access probing with stolen credentials detections + file: endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml + name: Probing Access with Stolen Credentials via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml new file mode 100644 index 0000000000..af78d4cb23 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml @@ -0,0 +1,85 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery of accounts and groups and access + to them.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 +known_false_positives: None identified. +name: Reconnaissance and Access to Accounts and Groups via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is searching for and using specific accounts and groups. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is searching for and using specific accounts and groups. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1078 + - T1087 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml new file mode 100644 index 0000000000..48aac644b9 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml @@ -0,0 +1,109 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover accounts, groups and policies + that can be accessed or taken over.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 63422f8e-766c-468f-8133-2ba6795e263b +known_false_positives: None identified. +name: Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for and using specific accounts, groups + and policies, such as the last logged on account, a local Net group, etc. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true + OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, + /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true + OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, + /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true + OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, + /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true + OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true + OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, + /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true + OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, + /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true + OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true + OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, + /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true + OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true + OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true + OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, + /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true + OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, + /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true + OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, + /(?i)Get-LastLoggedOn/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for and using specific accounts, groups + and policies, such as the last logged on account, a local Net group, etc. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1078 + - T1087 + - T1484 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml new file mode 100644 index 0000000000..9cd26d09f7 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml @@ -0,0 +1,98 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules for reconnaissance and access to elements + of Active Directory infrastructure, such as domain identifiers, AD sites and forests, + and trust relations.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: db08ac40-ee14-43e9-9a75-dddd059ef812 +known_false_positives: None identified. +name: Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is seaching for or accessing Active Directory objects + such as domain sites, domain trusts, AD forests, etc. Operation is performed at + the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR + match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true + OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true + OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, + /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true + OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true + OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true + OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, + /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true + OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is seaching for or accessing Active Directory objects + such as domain sites, domain trusts, AD forests, etc. Operation is performed at + the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1199 + - T1482 + - T1590 + - T1591 + - T1595 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml new file mode 100644 index 0000000000..9f677b78bb --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml @@ -0,0 +1,90 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover computers, servers and domains + that can be accessed or taken over.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: fe1c4c5a-09f3-4b43-8129-560a7f38a08b +known_false_positives: None identified. +name: Reconnaissance and Access to Computers and Domains via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is seaching for or accessing domain controllers, + computers, file servers, etc. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR + match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true + OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true + OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, + /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is seaching for or accessing domain controllers, computers, + file servers, etc. Operation is performed at the device $dest_device_id$, by the + account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1592 + - T1590 + - T1087 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml new file mode 100644 index 0000000000..4efdb3ecff --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml @@ -0,0 +1,81 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery of computers and servers and access + to them.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 +known_false_positives: None identified. +name: Reconnaissance and Access to Computers via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is collecting information about computers. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)net::ServerInfo/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 50 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is collecting information about computers. Operation is + performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ + mitre_attack_id: + - T1592 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 50 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml new file mode 100644 index 0000000000..1637bfac4c --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml @@ -0,0 +1,98 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover and access operating system + elements, such as processes, services, registry locations, security packages and + files.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: c1d33ad9-1727-4f9f-a474-4adbe4fed68a +known_false_positives: None identified. +name: Reconnaissance and Access to Operating System Elements via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for and tapping into ongoing processes, + mounted drives or other operating system elements. Operation is performed at the + device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true + OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, + /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR + match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true + OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true + OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, + /(?i)Get-RegistryMountedDrive/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for and tapping into ongoing processes, + mounted drives or other operating system elements. Operation is performed at the + device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1057 + - T1083 + - T1592.002 + - T1046 + - T1012 + - T1007 + - T1047 + - T1592 + - T1518 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml new file mode 100644 index 0000000000..cc69c9c467 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml @@ -0,0 +1,80 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery and access to services and processes.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 0243d37c-57c1-4182-bfd1-39b212255fc8 +known_false_positives: None identified. +name: Reconnaissance and Access to Processes and Services via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is listing processes and services. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 50 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is listing processes and services. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1007 + - T1046 + - T1057 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 50 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml new file mode 100644 index 0000000000..4ea264cc5b --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml @@ -0,0 +1,85 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery and access to network shares.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f +known_false_positives: None identified. +name: Reconnaissance and Access to Shared Resources via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)net::share/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Lateral Movement + - Stage:Collection + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1021 + - T1039 + - T1135 + - T1021.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml new file mode 100644 index 0000000000..dd4633a38e --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml @@ -0,0 +1,90 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover and access network and distributed + file system shares.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 6b7ca431-6b1e-4b40-9589-21cb368e369e +known_false_positives: None identified. +name: Reconnaissance and Access to Shared Resources via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true + OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, + /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true + OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, + /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Lateral Movement + - Stage:Collection + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1021 + - T1039 + - T1135 + - T1021.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml new file mode 100644 index 0000000000..c79a306b71 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml @@ -0,0 +1,101 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules that discover opportunities for malicious + access and persistence. Some examples include access to admin accounts, weak access + control policies, landing paths for dropping malicious software or data to exfiltrate, + registry locations to land autorun parameters, task scheduling opportunities, as + well as services and system files that can be compromised.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 +known_false_positives: None identified. +name: Reconnaissance of Access and Persistence Opportunities via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for an entry point into the infrastructure, + such as local admin accounts, opportunities to hijack processes, unattended install + files, or modifiable access objects. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true + OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, + /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true + OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, + /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true + OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, + /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true + OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, + /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true + OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, + /(?i)Get-UnquotedService/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is searching for an entry point into the infrastructure, + such as local admin accounts, opportunities to hijack processes, unattended install + files, or modifiable access objects. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1053 + - T1068 + - T1078 + - T1543 + - T1547 + - T1574 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 60 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml new file mode 100644 index 0000000000..4011dcfffe --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml @@ -0,0 +1,90 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules for reconnaissance of connectivity.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 +known_false_positives: None identified. +name: Reconnaissance of Connectivity via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is performing port scans or searching for various + connectivity details such as DNS data, proxies, or ongoing RDP connections. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true + OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, + /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true + OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, + /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true + OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true + ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is performing port scans or searching for various connectivity + details such as DNS data, proxies, or ongoing RDP connections. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1021 + - T1039 + - T1135 + - T1021.002 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml new file mode 100644 index 0000000000..cbfc35bd95 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml @@ -0,0 +1,91 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies reconnaissance of credential stores and use of CryptoAPI services by + Mimikatz modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 5facee5b-79e4-47ab-b0e6-c625acc0554f +known_false_positives: None identified. +name: Reconnaissance of Credential Stores and Services via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is searching for and accessing credential stores. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, + /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true + OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Credential Access + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is searching for and accessing credential stores. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1098 + - T1590.001 + - T1078 + - T1589.001 + - T1590 + - T1068 + - T1589 + - T1590.003 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 80 + risk_severity: high + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml new file mode 100644 index 0000000000..c100454874 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml @@ -0,0 +1,83 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules for assessment of presence of defensive tools.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 24b4e659-63a2-4e7b-89ac-87dd659c7110 +known_false_positives: None identified. +name: Reconnaissance of Defensive Tools via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is looking for presence of anti virus software. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Find-AVSignature/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 40 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is looking for presence of anti virus software. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1592.002 + - T1595.002 + - T1592 + - T1595 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 40 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml new file mode 100644 index 0000000000..a919f28981 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml @@ -0,0 +1,82 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules for assessment of privilege escalation opportunities.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: b9b4492c-2af8-449b-beb4-b1b78d963321 +known_false_positives: None identified. +name: Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is engaging its privilege escalation module. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Invoke-PrivescAudit/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is engaging its privilege escalation module. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 60 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml new file mode 100644 index 0000000000..0232e39486 --- /dev/null +++ b/dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml @@ -0,0 +1,90 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery of process or service hijacking + opportunities via Microsoft Detours compatibility. Microsoft Detours is an open + source library for intercepting, monitoring and instrumenting binary functions on + Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory + code for target functions. The Detours package also contains utilities to attach + arbitrary DLLs and data segments called payloads to any Win32 binary.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: fc5c1cbd-7494-4314-aad2-458d6fd4fada +known_false_positives: None identified. +name: Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +- https://en.wikipedia.org/wiki/Microsoft_Detours +risk_message: Mimikatz malware is looking for and invoking Microsoft Detours package + that enables spoofing of in-memory code. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)misc::detours/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Discovery Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Recon + - Stage:Command And Control + - Consequence:Loss Of Control + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is looking for and invoking Microsoft Detours package + that enables spoofing of in-memory code. Operation is performed at the device + $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1543 + - T1055 + - T1574 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - process + - dest_device_id + - dest_user_id + risk_score: 70 + risk_severity: low + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___resize_shadowstorage_volume.yml b/dist/ssa/srs/ssa___resize_shadowstorage_volume.yml new file mode 100644 index 0000000000..aeb81926a4 --- /dev/null +++ b/dist/ssa/srs/ssa___resize_shadowstorage_volume.yml @@ -0,0 +1,105 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: The following analytic identifies the resizing of shadowstorage using + vssadmin.exe to avoid the shadow volumes being made again. This technique is typically + found used by adversaries during a ransomware event and a precursor to deleting + the shadowstorage. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: dbc30554-d27e-11eb-9e5e-acde48001122 +known_false_positives: System administrators may resize the shadowstorage for valid + purposes. Filter as needed. +name: Resize Shadowstorage Volume +product: +- Splunk Behavioral Analytics +references: +- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html +- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow + copy to perform offline password cracking. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%resize%") AND like(cmd_line, "%shadowstorage%") + AND like(cmd_line, "%maxsize%") AND process_name="vssadmin.exe" | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - Clop Ransomware + - Ransomware + cis20: + - CIS 10 + - CIS 13 + confidence: 80 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow + copy to perform offline password cracking. + mitre_attack_id: + - T1489 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 64 + risk_severity: low + security_domain: endpoint +test: + name: Resize Shadowstorage Volume Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test for resizing the shadow storage of a machine + file: endpoint/ssa___resize_shadowstorage_volume.yml + name: Resize Shadowstorage Volume + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/srs/ssa___sdelete_application_execution.yml b/dist/ssa/srs/ssa___sdelete_application_execution.yml new file mode 100644 index 0000000000..53541e83fe --- /dev/null +++ b/dist/ssa/srs/ssa___sdelete_application_execution.yml @@ -0,0 +1,110 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-15' +description: This analytic will detect the execution of sdelete.exe attempting to + delete potentially important files that may related to adversary or insider threats + to destroy evidence or information sabotage. Sdelete is a SysInternals utility meant + to securely delete files on disk. This tool is commonly used to clear tracks and + artifact on the targeted host. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +id: fcc52b9a-4616-11ec-8454-acde48001122 +known_false_positives: False positives should be limited, filter as needed. +name: Sdelete Application Execution +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md +risk_message: Sdelete process $process_name$ executed on $dest_device_id$ attempting + to permanently delete files by $dest_user_id$. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), + "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), + parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), parent_cmd_line=ucast(map_get(input_event, "parent_process"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line + IS NOT NULL AND process_name IS NOT NULL AND like(process_name, "%sdelete%") AND + (like (cmd_line, "%-c %") OR like (cmd_line, "%-f %")OR like (cmd_line, "%-p %") + OR like (cmd_line, "%-r %") OR like (cmd_line, "%-q %") OR like (cmd_line, "%-s + %") OR like (cmd_line, "%-z %") OR like (cmd_line, "%/accepteula%") OR like (cmd_line, + "%-nobanner%")OR like (cmd_line, "%.doc%")OR like (cmd_line, "%.xls%") OR like (cmd_line, + "%.ppt%")OR like (cmd_line, "%.rtf%") OR like (cmd_line, "%.pdf%") OR like (cmd_line, + "%.key%")OR like (cmd_line, "%.log%") OR like (cmd_line, "%.txt%") OR like (cmd_line, + "%.jpg%") OR like (cmd_line, "%.png%") OR like (cmd_line, "%.gif%") OR like (cmd_line, + "%.bmp%") OR like (cmd_line, "%.7z%") OR like (cmd_line, "%.zip%") OR like (cmd_line, + "%.rar%") OR like (cmd_line, "%.tar%") OR like (cmd_line, "%.gz%") OR like (cmd_line, + "%.xls%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "process_path", process_path, "parent_process_name", parent_process_name, + "parent_cmd_line", parent_cmd_line]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Information Sabotage + confidence: 70 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log + impact: 60 + kill_chain_phases: + - Exploitation + message: Sdelete process $process_name$ executed on $dest_device_id$ attempting + to permanently delete files by $dest_user_id$. + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest + - user + - parent_process_name + - parent_process + - process_name + - process + - process_id + - process_path + - cmd_line + risk_score: 42 + risk_severity: medium + security_domain: endpoint +test: + name: Sdelete Application Execution Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log + file_name: security.log + source: WinEventLog:Security + description: Test for sdelete execution command + file: endpoint/ssa___sdelete_application_execution.yml + name: Sdelete Application Execution + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml new file mode 100644 index 0000000000..f91f7f5062 --- /dev/null +++ b/dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml @@ -0,0 +1,106 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies illegal setting of credentials via DSInternals modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c +known_false_positives: None identified. +name: Setting Credentials via DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +risk_message: DSInternals malware is accessing, using or setting Active Directory + or Azure credentials and accounts. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, + "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true + OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true + OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, + /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true + OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Source:Cloud Data + - Stage:Credential Access + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: DSInternals malware is accessing, using or setting Active Directory or + Azure credentials and accounts. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - parent_process_name + - _time + - process_path + - dest_user_id + - process + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Setting Credentials via DSInternals modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + file_name: logAllDSInternalsModules.log + source: WinEventLog:Security + description: Test illegal credential setting detections + file: endpoint/ssa___setting_credentials_via_dsinternals_modules.yml + name: Setting Credentials via DSInternals modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml new file mode 100644 index 0000000000..f2771dd531 --- /dev/null +++ b/dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml @@ -0,0 +1,96 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies illegal setting of credentials via Mimikatz modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: c8b84699-7652-4363-910f-efd1ca82f780 +known_false_positives: None identified. +name: Setting Credentials via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is accessing, using or setting account credentials. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: Mimikatz malware is accessing, using or setting account credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Setting Credentials via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test illegal credential setting detections + file: endpoint/ssa___setting_credentials_via_mimikatz_modules.yml + name: Setting Credentials via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml b/dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml new file mode 100644 index 0000000000..2cfe008d54 --- /dev/null +++ b/dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml @@ -0,0 +1,96 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies illegal setting of credentials via PowerSploit modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 07b2a501-f967-4ddc-9f56-2dce46dfce44 +known_false_positives: None identified. +name: Setting Credentials via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is setting passwords on Active Directory accounts. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, + /(?i)Set-DomainUserPassword/)=true ) + + | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Persistence Techniques + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Consequence:Loss Of Control + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log + impact: 90 + kill_chain_phases: + - Actions on Objectives + message: PowerSploit malware is setting passwords on Active Directory accounts. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ + mitre_attack_id: + - T1068 + - T1078 + - T1098 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - dest_user_id + - process + - _time + risk_score: 90 + risk_severity: high + security_domain: endpoint +test: + name: Setting Credentials via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test illegal credential setting detections + file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml + name: Setting Credentials via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml b/dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml new file mode 100644 index 0000000000..dd623108e9 --- /dev/null +++ b/dist/ssa/srs/ssa___system_process_running_from_unexpected_location.yml @@ -0,0 +1,280 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2020-08-25' +description: An attacker tries might try to use different version of a system command + without overriding original, or they might try to avoid some detection running the + process from a different folder. This detection checks that a list of system processes + run inside C:\\Windows\System32 or C:\\Windows\SysWOW64 The list of system processes + has been extracted from https://github.com/splunk/security_content/blob/develop/lookups/is_windows_system_file.csv + and the original detection https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml +how_to_implement: Collect endpoint data such as sysmon or 4688 events. +id: 28179107-099a-464a-94d3-08301e6c055f +known_false_positives: None +name: System Process Running from Unexpected Location +product: +- Splunk Behavioral Analytics +references: [] +risk_message: A system process $process_name$ with commandline $cmd_line$ spawn in + non-default folder path in host $dest_device_id$ +search: ' $ssa_input = | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), + "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", + null)), event_id=ucast(map_get(input_event, "event_id"), "string", null); + + $cond_1 = | from $ssa_input | where process_name="arp.exe" OR process_name="adaptertroubleshooter.exe" + OR process_name="applicationframehost.exe" OR process_name="atbroker.exe" OR process_name="authhost.exe" + OR process_name="autoworkplace.exe" OR process_name="axinstui.exe" OR process_name="backgroundtransferhost.exe" + OR process_name="bdehdcfg.exe" OR process_name="bdeuisrv.exe" OR process_name="bdeunlockwizard.exe" + OR process_name="bitlockerdeviceencryption.exe" OR process_name="bitlockerwizard.exe" + OR process_name="bitlockerwizardelev.exe" OR process_name="bytecodegenerator.exe" + OR process_name="camerasettingsuihost.exe" OR process_name="castsrv.exe" OR process_name="certenrollctrl.exe" + OR process_name="checknetisolation.exe" OR process_name="clipup.exe" OR process_name="cloudexperiencehostbroker.exe" + OR process_name="cloudnotifications.exe" OR process_name="cloudstoragewizard.exe" + OR process_name="compmgmtlauncher.exe" OR process_name="compattelrunner.exe" OR + process_name="computerdefaults.exe" OR process_name="credentialuibroker.exe" OR + process_name="dfdwiz.exe" OR process_name="dwwin.exe" OR process_name="dataexchangehost.exe" + OR process_name="defrag.exe" OR process_name="devicedisplayobjectprovider.exe" OR + process_name="deviceeject.exe" OR process_name="deviceenroller.exe" OR process_name="devicepairingwizard.exe" + OR process_name="deviceproperties.exe" OR process_name="disksnapshot.exe" OR process_name="dism.exe" + OR process_name="displayswitch.exe" OR process_name="dmnotificationbroker.exe" OR + process_name="dmomacpmo.exe" OR process_name="dpiscaling.exe" OR process_name="dsmusertask.exe" + OR process_name="dxpserver.exe" OR process_name="edpcleanup.exe" OR process_name="eosnotify.exe" + OR process_name="eap3host.exe" OR process_name="easpoliciesbrokerhost.exe" OR process_name="easeofaccessdialog.exe" + OR process_name="ehstorauthn.exe" OR process_name="fxscover.exe" OR process_name="fxssvc.exe" + OR process_name="fxsunatd.exe" OR process_name="filehistory.exe" OR process_name="fondue.exe" + OR process_name="gamepanel.exe" OR process_name="genvalobj.exe" OR process_name="gettingstarted.exe" + OR process_name="hostname.exe" OR process_name="icsentitlementhost.exe" OR process_name="infdefaultinstall.exe" + OR process_name="installagent.exe" OR process_name="languagecomponentsinstallercomhandler.exe" + OR process_name="launchtm.exe" OR process_name="launchwinapp.exe" OR process_name="legacynetuxhost.exe" + OR process_name="licensemanagershellext.exe" OR process_name="licensingui.exe" OR + process_name="locationnotificationwindows.exe" OR process_name="locationnotifications.exe" + OR process_name="locator.exe" OR process_name="lockapphost.exe" OR process_name="lockscreencontentserver.exe" + OR process_name="logonui.exe" OR process_name="lsaiso.exe" OR process_name="mdeserver.exe" + OR process_name="mdmagent.exe" OR process_name="mdmappinstaller.exe" OR process_name="mrinfo.exe" + OR process_name="mrt.exe" OR process_name="mschedexe.exe" OR process_name="magnify.exe" + OR process_name="mbaeparsertask.exe" OR process_name="mdres.exe" OR process_name="mdsched.exe" + OR process_name="migautoplay.exe" OR process_name="mpsigstub.exe" OR process_name="msspellcheckinghost.exe" + OR process_name="muiunattend.exe" OR process_name="multidigimon.exe" OR process_name="musnotification.exe" + OR process_name="musnotificationux.exe" OR process_name="napstat.exe" OR process_name="netstat.exe" + OR process_name="narrator.exe" OR process_name="netcfgnotifyobjecthost.exe" OR process_name="netevtfwdr.exe" + OR process_name="netproj.exe" OR process_name="netplwiz.exe" OR process_name="networkuxbroker.exe"; + + $cond_2 = | from $ssa_input | where process_name="openwith.exe" OR process_name="optionalfeatures.exe" + OR process_name="pathping.exe" OR process_name="ping.exe" OR process_name="passwordonwakesettingflyout.exe" + OR process_name="pickerhost.exe" OR process_name="pkgmgr.exe" OR process_name="pnpunattend.exe" + OR process_name="pnputil.exe" OR process_name="presentationhost.exe" OR process_name="presentationsettings.exe" + OR process_name="printbrmui.exe" OR process_name="printdialoghost.exe" OR process_name="printdialoghost3d.exe" + OR process_name="printisolationhost.exe" OR process_name="proximityuxhost.exe" OR + process_name="rdspnf.exe" OR process_name="rmactivate.exe" OR process_name="rmactivate_isv.exe" + OR process_name="rmactivate_ssp.exe" OR process_name="rmactivate_ssp_isv.exe" OR + process_name="route.exe" OR process_name="rdpsa.exe" OR process_name="rdpsaproxy.exe" + OR process_name="rdpsauachelper.exe" OR process_name="reagentc.exe" OR process_name="recoverydrive.exe" + OR process_name="register-cimprovider.exe" OR process_name="registeriepkeys.exe" + OR process_name="relpost.exe" OR process_name="remoteposworker.exe" OR process_name="rmclient.exe" + OR process_name="robocopy.exe" OR process_name="rpcping.exe" OR process_name="runlegacycplelevated.exe" + OR process_name="runtimebroker.exe" OR process_name="sihclient.exe" OR process_name="searchfilterhost.exe" + OR process_name="searchindexer.exe" OR process_name="searchprotocolhost.exe" OR + process_name="secedit.exe" OR process_name="sensordataservice.exe" OR process_name="setieinstalleddate.exe" + OR process_name="settingsynchost.exe" OR process_name="slidetoshutdown.exe" OR process_name="smartscreensettings.exe" + OR process_name="sndvol.exe" OR process_name="snippingtool.exe" OR process_name="soundrecorder.exe" + OR process_name="spaceagent.exe" OR process_name="sppextcomobj.exe" OR process_name="srtasks.exe" + OR process_name="stikynot.exe" OR process_name="synchost.exe" OR process_name="sysreseterr.exe" + OR process_name="systempropertiesadvanced.exe" OR process_name="systempropertiescomputername.exe" + OR process_name="systempropertiesdataexecutionprevention.exe" OR process_name="systempropertieshardware.exe" + OR process_name="systempropertiesperformance.exe" OR process_name="systempropertiesprotection.exe" + OR process_name="systempropertiesremote.exe" OR process_name="systemsettingsadminflows.exe" + OR process_name="systemsettingsbroker.exe" OR process_name="systemsettingsremovedevice.exe" + OR process_name="tcpsvcs.exe" OR process_name="tracert.exe" OR process_name="tstheme.exe" + OR process_name="tswbprxy.exe" OR process_name="tapiunattend.exe" OR process_name="taskmgr.exe" + OR process_name="thumbnailextractionhost.exe" OR process_name="tokenbrokercookies.exe" + OR process_name="tpminit.exe" OR process_name="tswpfwrp.exe" OR process_name="ui0detect.exe" + OR process_name="upgraderesultsui.exe" OR process_name="useraccountbroker.exe" OR + process_name="useraccountcontrolsettings.exe" OR process_name="usoclient.exe" OR + process_name="utilman.exe" OR process_name="vssvc.exe" OR process_name="vaultcmd.exe" + OR process_name="vaultsysui.exe" OR process_name="wfs.exe" OR process_name="wmpdmc.exe" + OR process_name="wpdshextautoplay.exe" OR process_name="wscollect.exe" OR process_name="wsmanhttpconfig.exe" + OR process_name="wsreset.exe" OR process_name="wudfhost.exe" OR process_name="wwahost.exe" + OR process_name="wallpaperhost.exe" OR process_name="webcache.exe" OR process_name="werfault.exe" + OR process_name="werfaultsecure.exe" OR process_name="winsat.exe" OR process_name="windows.media.backgroundplayback.exe" + OR process_name="windowsactiondialog.exe" OR process_name="windowsanytimeupgrade.exe" + OR process_name="windowsanytimeupgraderesults.exe"; + + $cond_3 = | from $ssa_input | where process_name="windowsanytimeupgradeui.exe" OR + process_name="windowsupdateelevatedinstaller.exe" OR process_name="workfolders.exe" + OR process_name="wpcmon.exe" OR process_name="acu.exe" OR process_name="aitagent.exe" + OR process_name="aitstatic.exe" OR process_name="alg.exe" OR process_name="appidcertstorecheck.exe" + OR process_name="appidpolicyconverter.exe" OR process_name="at.exe" OR process_name="attrib.exe" + OR process_name="audiodg.exe" OR process_name="auditpol.exe" OR process_name="autochk.exe" + OR process_name="autoconv.exe" OR process_name="autofmt.exe" OR process_name="baaupdate.exe" + OR process_name="backgroundtaskhost.exe" OR process_name="bcastdvr.exe" OR process_name="bcdboot.exe" + OR process_name="bcdedit.exe" OR process_name="bdechangepin.exe" OR process_name="bdeunlock.exe" + OR process_name="bitsadmin.exe" OR process_name="bootcfg.exe" OR process_name="bootim.exe" + OR process_name="bootsect.exe" OR process_name="bridgeunattend.exe" OR process_name="browser_broker.exe" + OR process_name="bthudtask.exe" OR process_name="cacls.exe" OR process_name="calc.exe" + OR process_name="cdpreference.exe" OR process_name="certreq.exe" OR process_name="certutil.exe" + OR process_name="change.exe" OR process_name="changepk.exe" OR process_name="charmap.exe" + OR process_name="chglogon.exe" OR process_name="chgport.exe" OR process_name="chgusr.exe" + OR process_name="chkdsk.exe" OR process_name="chkntfs.exe" OR process_name="choice.exe" + OR process_name="cipher.exe" OR process_name="cleanmgr.exe" OR process_name="cliconfg.exe" + OR process_name="clip.exe" OR process_name="cmd.exe" OR process_name="cmdkey.exe" + OR process_name="cmdl32.exe" OR process_name="cmmon32.exe" OR process_name="cmstp.exe" + OR process_name="cofire.exe" OR process_name="colorcpl.exe" OR process_name="comp.exe" + OR process_name="compact.exe" OR process_name="conhost.exe" OR process_name="consent.exe" + OR process_name="control.exe" OR process_name="convert.exe" OR process_name="credwiz.exe" + OR process_name="cscript.exe" OR process_name="csrss.exe" OR process_name="ctfmon.exe" + OR process_name="cttune.exe" OR process_name="cttunesvr.exe" OR process_name="dashost.exe" + OR process_name="dccw.exe" OR process_name="dcomcnfg.exe" OR process_name="ddodiag.exe" + OR process_name="dfrgui.exe" OR process_name="dialer.exe" OR process_name="diantz.exe" + OR process_name="dinotify.exe" OR process_name="diskpart.exe" OR process_name="diskperf.exe" + OR process_name="diskraid.exe" OR process_name="dispdiag.exe" OR process_name="djoin.exe" + OR process_name="dllhost.exe" OR process_name="dllhst3g.exe" OR process_name="dmcertinst.exe" + OR process_name="dmcfghost.exe" OR process_name="dmclient.exe" OR process_name="dnscacheugc.exe" + OR process_name="doskey.exe" OR process_name="dpapimig.exe" OR process_name="dpnsvr.exe" + OR process_name="driverquery.exe" OR process_name="drvcfg.exe" OR process_name="drvinst.exe" + OR process_name="dsregcmd.exe" OR process_name="dstokenclean.exe" OR process_name="dvdplay.exe" + OR process_name="dvdupgrd.exe" OR process_name="dwm.exe" OR process_name="dxdiag.exe" + OR process_name="easinvoker.exe" OR process_name="efsui.exe"; + + $cond_4 = | from $ssa_input | where process_name="embeddedapplauncher.exe" OR process_name="esentutl.exe" + OR process_name="eudcedit.exe" OR process_name="eventcreate.exe" OR process_name="eventvwr.exe" + OR process_name="expand.exe" OR process_name="extrac32.exe" OR process_name="fc.exe" + OR process_name="fhmanagew.exe" OR process_name="find.exe" OR process_name="findstr.exe" + OR process_name="finger.exe" OR process_name="fixmapi.exe" OR process_name="fltmc.exe" + OR process_name="fodhelper.exe" OR process_name="fontdrvhost.exe" OR process_name="fontview.exe" + OR process_name="forfiles.exe" OR process_name="fsavailux.exe" OR process_name="fsquirt.exe" + OR process_name="fsutil.exe" OR process_name="ftp.exe" OR process_name="fvenotify.exe" + OR process_name="fveprompt.exe" OR process_name="getmac.exe" OR process_name="gpresult.exe" + OR process_name="gpscript.exe" OR process_name="gpupdate.exe" OR process_name="grpconv.exe" + OR process_name="hdwwiz.exe" OR process_name="help.exe" OR process_name="hwrcomp.exe" + OR process_name="hwrreg.exe" OR process_name="icacls.exe" OR process_name="icardagt.exe" + OR process_name="icsunattend.exe" OR process_name="ie4uinit.exe" OR process_name="ieunatt.exe" + OR process_name="ieetwcollector.exe" OR process_name="iexpress.exe" OR process_name="immersivetpmvscmgrsvr.exe" + OR process_name="ipconfig.exe" OR process_name="irftp.exe" OR process_name="iscsicli.exe" + OR process_name="iscsicpl.exe" OR process_name="isoburn.exe" OR process_name="klist.exe" + OR process_name="ksetup.exe" OR process_name="ktmutil.exe" OR process_name="label.exe" + OR process_name="licensingdiag.exe" OR process_name="lodctr.exe" OR process_name="logagent.exe" + OR process_name="logman.exe" OR process_name="logoff.exe" OR process_name="lpkinstall.exe" + OR process_name="lpksetup.exe" OR process_name="lpremove.exe" OR process_name="lsass.exe" + OR process_name="lsm.exe" OR process_name="makecab.exe" OR process_name="manage-bde.exe" + OR process_name="mblctr.exe" OR process_name="mcbuilder.exe" OR process_name="mctadmin.exe" + OR process_name="mfpmp.exe" OR process_name="mmc.exe" OR process_name="mobsync.exe" + OR process_name="mountvol.exe" OR process_name="mpnotify.exe" OR process_name="msconfig.exe" + OR process_name="msdt.exe" OR process_name="msdtc.exe" OR process_name="msfeedssync.exe" + OR process_name="msg.exe" OR process_name="mshta.exe" OR process_name="msiexec.exe" + OR process_name="msinfo32.exe" OR process_name="mspaint.exe" OR process_name="msra.exe" + OR process_name="mstsc.exe" OR process_name="mtstocom.exe" OR process_name="nbtstat.exe" + OR process_name="ndadmin.exe" OR process_name="net.exe" OR process_name="net1.exe" + OR process_name="netbtugc.exe" OR process_name="netcfg.exe" OR process_name="netiougc.exe" + OR process_name="netsh.exe" OR process_name="newdev.exe" OR process_name="nltest.exe" + OR process_name="notepad.exe" OR process_name="nslookup.exe" OR process_name="ntoskrnl.exe" + OR process_name="ntprint.exe" OR process_name="ocsetup.exe" OR process_name="odbcad32.exe" + OR process_name="odbcconf.exe" OR process_name="omadmclient.exe" OR process_name="omadmprc.exe"; + + $cond_5 = | from $ssa_input | where process_name="openfiles.exe" OR process_name="osk.exe" + OR process_name="p2phost.exe" OR process_name="pcalua.exe" OR process_name="pcaui.exe" + OR process_name="pcawrk.exe" OR process_name="pcwrun.exe" OR process_name="perfmon.exe" + OR process_name="phoneactivate.exe" OR process_name="plasrv.exe" OR process_name="poqexec.exe" + OR process_name="powercfg.exe" OR process_name="prevhost.exe" OR process_name="print.exe" + OR process_name="printfilterpipelinesvc.exe" OR process_name="printui.exe" OR process_name="proquota.exe" + OR process_name="provtool.exe" OR process_name="psr.exe" OR process_name="pwlauncher.exe" + OR process_name="qappsrv.exe" OR process_name="qprocess.exe" OR process_name="query.exe" + OR process_name="quser.exe" OR process_name="qwinsta.exe" OR process_name="rasautou.exe" + OR process_name="rasdial.exe" OR process_name="raserver.exe" OR process_name="rasphone.exe" + OR process_name="rdpclip.exe" OR process_name="rdpinput.exe" OR process_name="rdrleakdiag.exe" + OR process_name="recdisc.exe" OR process_name="recover.exe" OR process_name="reg.exe" + OR process_name="regedt32.exe" OR process_name="regini.exe" OR process_name="regsvr32.exe" + OR process_name="rekeywiz.exe" OR process_name="relog.exe" OR process_name="repair-bde.exe" + OR process_name="replace.exe" OR process_name="reset.exe" OR process_name="resmon.exe" + OR process_name="rmttpmvscmgrsvr.exe" OR process_name="rrinstaller.exe" OR process_name="rstrui.exe" + OR process_name="runas.exe" OR process_name="rundll32.exe" OR process_name="runonce.exe" + OR process_name="rwinsta.exe" OR process_name="sbunattend.exe" OR process_name="sc.exe" + OR process_name="schtasks.exe" OR process_name="sdbinst.exe" OR process_name="sdchange.exe" + OR process_name="sdclt.exe" OR process_name="sdiagnhost.exe" OR process_name="secinit.exe" + OR process_name="services.exe" OR process_name="sessionmsg.exe" OR process_name="sethc.exe" + OR process_name="setspn.exe" OR process_name="setupcl.exe" OR process_name="setupugc.exe" + OR process_name="setx.exe" OR process_name="sfc.exe" OR process_name="shadow.exe" + OR process_name="shrpubw.exe" OR process_name="shutdown.exe" OR process_name="sigverif.exe" + OR process_name="sihost.exe" OR process_name="slui.exe" OR process_name="smss.exe" + OR process_name="snmptrap.exe" OR process_name="sort.exe" OR process_name="spinstall.exe" + OR process_name="spoolsv.exe" OR process_name="sppsvc.exe" OR process_name="spreview.exe" + OR process_name="srdelayed.exe" OR process_name="subst.exe" OR process_name="svchost.exe" + OR process_name="sxstrace.exe" OR process_name="syskey.exe" OR process_name="systeminfo.exe" + OR process_name="systemreset.exe" OR process_name="systray.exe" OR process_name="tabcal.exe" + OR process_name="takeown.exe" OR process_name="taskeng.exe" OR process_name="taskhost.exe" + OR process_name="taskhostw.exe" OR process_name="taskkill.exe" OR process_name="tasklist.exe" + OR process_name="taskmgr.exe" OR process_name="tcmsetup.exe" OR process_name="timeout.exe" + OR process_name="tpmvscmgr.exe" OR process_name="tpmvscmgrsvr.exe"; + + $cond_6 = | from $ssa_input | where process_name="tracerpt.exe" OR process_name="tscon.exe" + OR process_name="tsdiscon.exe" OR process_name="tskill.exe" OR process_name="typeperf.exe" + OR process_name="tzsync.exe" OR process_name="tzutil.exe" OR process_name="ucsvc.exe" + OR process_name="unlodctr.exe" OR process_name="unregmp2.exe" OR process_name="upnpcont.exe" + OR process_name="userinit.exe" OR process_name="vds.exe" OR process_name="vdsldr.exe" + OR process_name="verclsid.exe" OR process_name="verifier.exe" OR process_name="verifiergui.exe" + OR process_name="vmicsvc.exe" OR process_name="vssadmin.exe" OR process_name="w32tm.exe" + OR process_name="waitfor.exe" OR process_name="wbadmin.exe" OR process_name="wbengine.exe" + OR process_name="wecutil.exe" OR process_name="wermgr.exe" OR process_name="wevtutil.exe" + OR process_name="wextract.exe" OR process_name="where.exe" OR process_name="whoami.exe" + OR process_name="wiaacmgr.exe" OR process_name="wiawow64.exe" OR process_name="wifitask.exe" + OR process_name="wimserv.exe" OR process_name="wininit.exe" OR process_name="winload.exe" + OR process_name="winlogon.exe" OR process_name="winresume.exe" OR process_name="winrs.exe" + OR process_name="winrshost.exe" OR process_name="winver.exe" OR process_name="wisptis.exe" + OR process_name="wkspbroker.exe" OR process_name="wksprt.exe" OR process_name="wlanext.exe" + OR process_name="wlrmdr.exe" OR process_name="wowreg32.exe" OR process_name="wpnpinst.exe" + OR process_name="wpr.exe" OR process_name="write.exe" OR process_name="wscript.exe" + OR process_name="wsmprovhost.exe" OR process_name="wsqmcons.exe" OR process_name="wuapihost.exe" + OR process_name="wuapp.exe" OR process_name="wuauclt.exe" OR process_name="wusa.exe" + OR process_name="xcopy.exe" OR process_name="xpsrchvw.exe" OR process_name="xwizard.exe"; + + | from $cond_1 | union $cond_2 | union $cond_3 | union $cond_4 | union $cond_5 | + union $cond_6 | where match_regex(process_path, /(?i)\\windows\\system32/)=false + AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(device, user), body=create_map(["event_id", + event_id, "process_path", process_path, "process_name", process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Defense Evasion Tactics + - Masquerading - Rename System Utilities + cis20: + - CIS 8 + confidence: 80 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/windows-security.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: A system process $process_name$ with commandline $cmd_line$ spawn in non-default + folder path in host $dest_device_id$ + mitre_attack_id: + - T1036 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - process_name + - _time + - dest_user_id + - process_path + risk_score: 56 + risk_severity: low + security_domain: endpoint +type: Anomaly +version: 3 diff --git a/dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml b/dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml new file mode 100644 index 0000000000..1d7a52b1dd --- /dev/null +++ b/dist/ssa/srs/ssa___wbadmin_delete_system_backups.yml @@ -0,0 +1,102 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator + Tool) that delete backup files. This is typically used by ransomware to prevent + recovery. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: 71efbf52-4dbb-4c00-a520-306aa546cbb7 +known_false_positives: Administrators may modify the boot configuration. +name: WBAdmin Delete System Backups +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md +- https://thedfirreport.com/2020/10/08/ryuks-return/ +- https://attack.mitre.org/techniques/T1490/ +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system + backups. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" + AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, + "%systemstatebackup%") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Ryuk Ransomware + - Ransomware + cis20: + - CIS 8 + confidence: 50 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: [] + impact: 30 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system + backups. + mitre_attack_id: + - T1490 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 15 + risk_severity: medium + security_domain: endpoint +test: + name: WBAdmin Delete System Backups - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + description: Test detection of WBAdmin Delete System Backups + file: endpoint/ssa___wbadmin_delete_system_backups.yml + name: WBAdmin Delete System Backups + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml b/dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml new file mode 100644 index 0000000000..aaeeca58e6 --- /dev/null +++ b/dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml @@ -0,0 +1,97 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-06-15' +description: The wevtutil.exe application is the windows event log utility. This searches + for wevtutil.exe with parameters for clearing the application, security, setup, + powershell, sysmon, or system event logs. +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +id: 5438113c-cdd9-11eb-93b8-acde48001122 +known_false_positives: The wevtutil.exe application is a legitimate Windows event + log utility. Administrators may use it to manage Windows event logs. +name: WevtUtil Usage To Clear Logs +product: +- Splunk Behavioral Analytics +references: +- https://www.splunk.com/en_us/blog/security/detecting-clop-ransomware.html +risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear + event logs in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, + /(?i)security/)=true OR match_regex(cmd_line, /(?i)system/)=true OR match_regex(cmd_line, + /(?i)sysmon/)=true OR match_regex(cmd_line, /(?i)application/)=true OR match_regex(cmd_line, + /(?i)setup/)=true OR match_regex(cmd_line, /(?i)powershell/)=true) AND process_name="wevtutil.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Log Manipulation + - Ransomware + - Clop Ransomware + cis20: + - CIS 8 + - CIS 13 + confidence: 90 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log + impact: 70 + kill_chain_phases: + - Exploitation + message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear + event logs in host $dest_device_id$ + mitre_attack_id: + - T1070 + - T1070.001 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + risk_score: 63 + risk_severity: low + security_domain: endpoint +test: + name: WevtUtil Usage To Clear Logs Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log + file_name: clear_evt.log + source: WinEventLog:Security + description: Test for wevtutil clear logs command + file: endpoint/ssa___wevtutil_usage_to_clear_logs.yml + name: WevtUtil Usage To Clear Logs + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml b/dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml new file mode 100644 index 0000000000..72fb55c1ca --- /dev/null +++ b/dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml @@ -0,0 +1,93 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-06-15' +description: This search is to detect execution of wevtutil.exe to disable logs. This + technique was seen in several ransomware to disable the event logs to evade alerts + and detections in compromised host. +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +id: a4bdc944-cdd9-11eb-ac97-acde48001122 +known_false_positives: network operator may disable audit event logs for debugging + purposes. +name: Wevtutil Usage To Disable Logs +product: +- Splunk Behavioral Analytics +references: +- https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/ +risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable + event logs in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, "%/e:false%") + AND process_name="wevtutil.exe" | eval start_time=timestamp, end_time=timestamp, + entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, + "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, + "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, + "process_path", process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Log Manipulation + - Ransomware + cis20: + - CIS 8 + - CIS 13 + confidence: 90 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log + impact: 70 + kill_chain_phases: + - Exploitation + message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable + event logs in host $dest_device_id$ + mitre_attack_id: + - T1070 + - T1070.001 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + risk_score: 63 + risk_severity: low + security_domain: endpoint +test: + name: Wevtutil Usage To Disable Logs Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log + file_name: disable_evt.log + source: WinEventLog:Security + description: Test for wevtutil disable logs command + file: endpoint/ssa___wevtutil_usage_to_disable_logs.yml + name: Wevtutil Usage To Disable Logs + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml b/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml new file mode 100644 index 0000000000..586a4f6173 --- /dev/null +++ b/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml @@ -0,0 +1,115 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-03' +description: 'The following analytic identifies the use of Windows Curl.exe uploading + a file to a remote destination. \ + + `-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. + \ + + `-d` or `--data` POST is the HTTP method that was invented to send data to a receiving + web application, and it is, for example, how most common HTML forms on the web work. + \ + + HTTP multipart formposts are done with `-F`, but this appears to not be compatible + with the Windows version of Curl. Will update if identified adversary tradecraft. + \ + + Adversaries may use one of the three methods based on the remote destination and + what they are attempting to upload (zip vs txt). During triage, review parallel + processes for further behavior. In addition, identify if the upload was successful + in network logs. If a file was uploaded, isolate the endpoint and review.' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: cc8d046a-543b-11ec-b864-acde48001122 +known_false_positives: False positives may be limited to source control applications + and may be required to be filtered out. +name: Windows Curl Upload to Remote Destination +product: +- Splunk Behavioral Analytics +references: +- https://everything.curl.dev/usingcurl/uploads +- https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409 +- https://twitter.com/d1r4c/status/1279042657508081664?s=20 +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote + destination. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="curl.exe" + AND (like (cmd_line, "%-T %") OR like (cmd_line, "%--upload-file %")OR like (cmd_line, + "%-d %") OR like (cmd_line, "%--data %") OR like (cmd_line, "%-F %")) + + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Ingress Tool Transfer + automated_detection_testing: passed + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log + impact: 80 + kill_chain_phases: + - Exfiltration + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote + destination. + mitre_attack_id: + - T1105 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Windows Curl Upload to Remote Destination Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:security + file: endpoint/ssa___windows_curl_upload_to_remote_destination.yml + name: Windows Curl Upload to Remote Destination + pass_condition: '@count_gt(0)' +type: TTP +version: 1 From 067b6e5bbea00dc9c4eafb78c22c3e33e7d82409 Mon Sep 17 00:00:00 2001 From: d1vious Date: Fri, 7 Jan 2022 16:04:51 -0500 Subject: [PATCH 2/9] cleaning up detections --- ...ssa___anomalous_usage_of_archive_tools.yml | 96 ------ ...tolen_credentials_via_mimikatz_modules.yml | 126 -------- ...en_credentials_via_powersploit_modules.yml | 121 -------- ...ntial_strength_via_dsinternals_modules.yml | 93 ------ .../ssa___attempt_to_delete_services.yml | 106 ------- .../ssa___attempt_to_disable_services.yml | 105 ------- ...dential_dump_from_registry_via_reg_exe.yml | 96 ------ ..._bcdedit_failure_recovery_modification.yml | 99 ------- ..._of_fgdump_and_cachedump_with_s_option.yml | 100 ------- ..._of_fgdump_and_cachedump_with_v_option.yml | 93 ------ ...cative_of_lazagne_command_line_options.yml | 85 ------ ...nternals_credential_conversion_modules.yml | 104 ------- ...dicative_of_use_of_dsinternals_modules.yml | 106 ------- ..._indicative_of_use_of_mimikatz_modules.yml | 90 ------ ...dicative_of_use_of_powersploit_modules.yml | 91 ------ ...crosoft_debuggers_peek_into_the_kernel.yml | 95 ------ ...ft_debuggers_via_z_command_line_option.yml | 91 ------ ...present_in_powersploit_and_dsinternals.yml | 86 ------ .../detections/ssa___delete_a_net_user.yml | 109 ------- ...___deny_permission_using_cacls_utility.yml | 92 ------ ...detect_dump_lsass_memory_using_comsvcs.yml | 87 ------ .../detections/ssa___detect_kerberoasting.yml | 94 ------ .../detections/ssa___detect_pass_the_hash.yml | 92 ------ ...ohibited_applications_spawning_cmd_exe.yml | 103 ------- ...ssa___detect_rclone_command-line_usage.yml | 97 ------ .../ssa___disable_net_user_account.yml | 104 ------- ...___dns_exfiltration_using_nslookup_app.yml | 104 ------- ...xcessive_number_of_office_files_copied.yml | 64 ---- ..._first_time_seen_command_line_argument.yml | 89 ------ .../detections/ssa___fsutil_zeroing_file.yml | 97 ------ ...__grant_permission_using_cacls_utility.yml | 92 ------ .../ssa___high_file_deletion_frequency.yml | 85 ------ ...o_user_content_via_powersploit_modules.yml | 92 ------ ...count_creation_via_powersploit_modules.yml | 93 ------ ..._deletion_of_logs_via_mimikatz_modules.yml | 83 ------ ...ng_of_accounts_via_dsinternals_modules.yml | 85 ------ ...s_and_policies_via_dsinternals_modules.yml | 89 ------ ...ctory_elements_via_powersploit_modules.yml | 90 ------ ...nd_persistence_via_powersploit_modules.yml | 104 ------- ...ivilege_elevation_via_mimikatz_modules.yml | 97 ------ ...d_process_control_via_mimikatz_modules.yml | 100 ------- ...rocess_control_via_powersploit_modules.yml | 110 ------- ...fy_acls_permission_of_files_or_folders.yml | 96 ------ ...lbas_applications_in_short_time_period.yml | 95 ------ ...ction_by_machine_learning_method_-_ssa.yml | 62 ---- ...ash_observed_at_the_destination_device.yml | 102 ------- ...observed_by_an_event_collecting_device.yml | 103 ------- ...en_credentials_via_powersploit_modules.yml | 96 ------ ...rare_parent-child_process_relationship.yml | 88 ------ ...counts_and_groups_via_mimikatz_modules.yml | 85 ------ ...s_and_policies_via_powersploit_modules.yml | 109 ------- ...infrastructure_via_powersploit_modules.yml | 98 ------ ...rs_and_domains_via_powersploit_modules.yml | 90 ------ ...cess_to_computers_via_mimikatz_modules.yml | 81 ----- ...ystem_elements_via_powersploit_modules.yml | 98 ------ ...sses_and_services_via_mimikatz_modules.yml | 80 ----- ..._shared_resources_via_mimikatz_modules.yml | 85 ------ ...ared_resources_via_powersploit_modules.yml | 90 ------ ..._opportunities_via_powersploit_modules.yml | 101 ------- ...f_connectivity_via_powersploit_modules.yml | 90 ------ ...ores_and_services_via_mimikatz_modules.yml | 91 ------ ...efensive_tools_via_powersploit_modules.yml | 83 ------ ..._opportunities_via_powersploit_modules.yml | 82 ----- ...ing_opportunities_via_mimikatz_modules.yml | 90 ------ .../ssa___resize_shadowstorage_volume.yml | 105 ------- .../ssa___sdelete_application_execution.yml | 110 ------- ...ng_credentials_via_dsinternals_modules.yml | 106 ------- ...tting_credentials_via_mimikatz_modules.yml | 96 ------ ...ng_credentials_via_powersploit_modules.yml | 96 ------ ...ocess_running_from_unexpected_location.yml | 280 ------------------ .../ssa___unusually_long_command_line.yml | 87 ------ .../ssa___wbadmin_delete_system_backups.yml | 102 ------- .../ssa___wevtutil_usage_to_clear_logs.yml | 97 ------ .../ssa___wevtutil_usage_to_disable_logs.yml | 93 ------ ...dows_curl_upload_to_remote_destination.yml | 115 ------- 75 files changed, 7317 deletions(-) delete mode 100644 dist/ssa/detections/ssa___anomalous_usage_of_archive_tools.yml delete mode 100644 dist/ssa/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml delete mode 100644 dist/ssa/detections/ssa___attempt_to_delete_services.yml delete mode 100644 dist/ssa/detections/ssa___attempt_to_disable_services.yml delete mode 100644 dist/ssa/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml delete mode 100644 dist/ssa/detections/ssa___bcdedit_failure_recovery_modification.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml delete mode 100644 dist/ssa/detections/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml delete mode 100644 dist/ssa/detections/ssa___delete_a_net_user.yml delete mode 100644 dist/ssa/detections/ssa___deny_permission_using_cacls_utility.yml delete mode 100644 dist/ssa/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml delete mode 100644 dist/ssa/detections/ssa___detect_kerberoasting.yml delete mode 100644 dist/ssa/detections/ssa___detect_pass_the_hash.yml delete mode 100644 dist/ssa/detections/ssa___detect_prohibited_applications_spawning_cmd_exe.yml delete mode 100644 dist/ssa/detections/ssa___detect_rclone_command-line_usage.yml delete mode 100644 dist/ssa/detections/ssa___disable_net_user_account.yml delete mode 100644 dist/ssa/detections/ssa___dns_exfiltration_using_nslookup_app.yml delete mode 100644 dist/ssa/detections/ssa___excessive_number_of_office_files_copied.yml delete mode 100644 dist/ssa/detections/ssa___first_time_seen_command_line_argument.yml delete mode 100644 dist/ssa/detections/ssa___fsutil_zeroing_file.yml delete mode 100644 dist/ssa/detections/ssa___grant_permission_using_cacls_utility.yml delete mode 100644 dist/ssa/detections/ssa___high_file_deletion_frequency.yml delete mode 100644 dist/ssa/detections/ssa___illegal_access_to_user_content_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_account_creation_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___modify_acls_permission_of_files_or_folders.yml delete mode 100644 dist/ssa/detections/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml delete mode 100644 dist/ssa/detections/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml delete mode 100644 dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml delete mode 100644 dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml delete mode 100644 dist/ssa/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___rare_parent-child_process_relationship.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___resize_shadowstorage_volume.yml delete mode 100644 dist/ssa/detections/ssa___sdelete_application_execution.yml delete mode 100644 dist/ssa/detections/ssa___setting_credentials_via_dsinternals_modules.yml delete mode 100644 dist/ssa/detections/ssa___setting_credentials_via_mimikatz_modules.yml delete mode 100644 dist/ssa/detections/ssa___setting_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/detections/ssa___system_process_running_from_unexpected_location.yml delete mode 100644 dist/ssa/detections/ssa___unusually_long_command_line.yml delete mode 100644 dist/ssa/detections/ssa___wbadmin_delete_system_backups.yml delete mode 100644 dist/ssa/detections/ssa___wevtutil_usage_to_clear_logs.yml delete mode 100644 dist/ssa/detections/ssa___wevtutil_usage_to_disable_logs.yml delete mode 100644 dist/ssa/detections/ssa___windows_curl_upload_to_remote_destination.yml diff --git a/dist/ssa/detections/ssa___anomalous_usage_of_archive_tools.yml b/dist/ssa/detections/ssa___anomalous_usage_of_archive_tools.yml deleted file mode 100644 index a0716cc96c..0000000000 --- a/dist/ssa/detections/ssa___anomalous_usage_of_archive_tools.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Patrick Bareiss, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-22' -description: The following detection identifies the usage of archive tools from the - command line. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 63614a58-10e2-4c6c-ae81-ea1113681439 -known_false_positives: False positives can be ligitmate usage of archive tools from - the command line. -name: Anomalous usage of Archive Tools -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1560/001/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading - of 7zip. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), - "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", - null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), - parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), parent_process=ucast(map_get(input_event, "parent_process"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name - IS NOT NULL AND parent_process_name IS NOT NULL | where like(process_name, "7z%") - OR process_name="WinRAR.exe" OR like(process_name, "winzip%") | where like(parent_process_name, - "%cmd.exe") OR like(parent_process_name, "%powershell.exe") | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name", - parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Cobalt Strike - - NOBELIUM Group - confidence: 60 - context: - - Source:Endpoint - - Stage:Collection - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log - impact: 70 - kill_chain_phases: - - Actions on Objective - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading - of 7zip. - mitre_attack_id: - - T1560.001 - - T1560 - observable: - - name: user - role: - - Victim - type: User - - name: dest - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - Processes.process_name - - Processes.process - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - risk_score: 42 - risk_severity: medium - security_domain: endpoint -test: - name: Anomalous usage of Archive Tools Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log - file_name: security.log - source: WinEventLog:Security - description: Test for Anomalous usage of Archive Tools - file: endpoint/ssa___anomalous_usage_of_archive_tools.yml - name: Anomalous usage of Archive Tools - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml deleted file mode 100644 index c2d7b5f6be..0000000000 --- a/dist/ssa/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml +++ /dev/null @@ -1,126 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifites the use of Mimikatz modules attempting to perform Pass-the-Ticket, - Golden or Silver Kerberos ticket attacks and Skeleton Key attack. This behavior - is typically performed within interactive Mimikatz memory space, however it may - be identified on the command-line. A Pass-the-Ticket (ptt) attack is performed once - an adversary has established access to a single endpoint and retrieved the kerberos - ticket to now begin moving laterally using this method. Typically, it blends in - with logon activity as the ticket can be copied to another system and passed into - the current session effectively simulating a logon without any communication with - the Domain Controller. A Golden or Silver ticket attack requires some setup by the - adversary, but once performed it will simulate lateral based authentication to additional - endpoints.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to Mimikatz. -name: Applying Stolen Credentials via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -- https://adsecurity.org/?p=1275 -- https://adsecurity.org/?p=1515 -- https://adsecurity.org/?page_id=1821#KERBEROSPTT -- https://attack.mitre.org/software/S0002/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash -risk_message: Mimikatz malware is violating authentication processes by injecting - golden or silver Kerberos tickets or passing stolen authentication tokens. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, - /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true - OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) | eval start_time = timestamp, - end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is violating authentication processes by injecting golden - or silver Kerberos tickets or passing stolen authentication tokens. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1068 - - T1078 - - T1098 - - T1134 - - T1543 - - T1547 - - T1548 - - T1554 - - T1556 - - T1558 - - T1558.002 - - T1558.001 - - T1003 - - T1003.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - - cmd_line - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Applying Stolen Credentials via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test applying stolen credentials detections - file: endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml - name: Applying Stolen Credentials via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml deleted file mode 100644 index dacb73b8b0..0000000000 --- a/dist/ssa/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,121 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies commonly used PowerSploit modules that perform credential access, - spoofing of authentication processes, user impersonation and attempting to manipulate - tokens. Specifically, the following modules `Invoke-CredentialInjection`, `Invoke-TokenManipulation`, - `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` were identfiied - as modules used to access credentials. PowerSploit is an archived project on GitHub, - but much of its modules and scripts are still utilized today by adversaries. This - behavior is typically performed within interactive PowerShell sessions or injected - into processes, however it may be identified on the command-line.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 270b482d-2af2-448f-9923-9cf005f61be4 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to PowerSploit. -name: Applying Stolen Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -- https://attack.mitre.org/software/S0194/ -risk_message: PowerSploit malware is violating authentication by injecting stolen - credentials, manipulating authentication tokens or impersonating system or user - accounts. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true - OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, - /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is violating authentication by injecting stolen credentials, - manipulating authentication tokens or impersonating system or user accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1068 - - T1078 - - T1098 - - T1134 - - T1543 - - T1547 - - T1548 - - T1554 - - T1555 - - T1558 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - - cmd_line - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Applying Stolen Credentials via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test applying stolen credentials detections - file: endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml - name: Applying Stolen Credentials via PowerSploit - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml b/dist/ssa/detections/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml deleted file mode 100644 index 81bc5ed977..0000000000 --- a/dist/ssa/detections/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, that - verifies password strength. Adversaries have utilized this module to determine password - complexity or to identify accounts with weak passwords.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Assessment of Credential Strength via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. - Account attempting this operation is $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Test-PasswordQuality/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 85 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 30 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. - Account attempting this operation is $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - - T1087 - - T1201 - - T1552 - - T1555 - - T1059.001 - - T1059 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - - cmd_line - risk_score: 25 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___attempt_to_delete_services.yml b/dist/ssa/detections/ssa___attempt_to_delete_services.yml deleted file mode 100644 index 043cbf7607..0000000000 --- a/dist/ssa/detections/ssa___attempt_to_delete_services.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Teoderick Contreras, splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -description: The following analytic identifies Windows Service Control, `sc.exe`, - attempting to delete a service. This is typically identified in parallel with other - instances of service enumeration of attempts to stop a service and then delete it. - Adversaries utilize this technique to terminate security services or other related - services to continue there objective and evade detections. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: a0c8c292-d01a-11eb-aa18-acde48001122 -known_false_positives: It is possible administrative scripts may start/stop/delete - services. Filter as needed. -name: Attempt To Delete Services -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%delete%") AND process_name = "sc.exe" - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 8 - - CIS 13 - confidence: 60 - context: - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Persistence - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log - impact: 60 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. - mitre_attack_id: - - T1489 - - T1543 - - T1543.003 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 36 - risk_severity: medium - security_domain: endpoint -test: - name: Attempt To delete Services Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log - file_name: sc_del.log - source: WinEventLog:Security - description: Test for usage of sc.exe to delete a service - file: endpoint/ssa___attempt_to_delete_services.yml - name: Attempt To delete Services - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/detections/ssa___attempt_to_disable_services.yml b/dist/ssa/detections/ssa___attempt_to_disable_services.yml deleted file mode 100644 index 869d013f4b..0000000000 --- a/dist/ssa/detections/ssa___attempt_to_disable_services.yml +++ /dev/null @@ -1,105 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -description: The following analytic identifies Windows Service Control, `sc.exe`, - attempting to disable a service. This is typically identified in parallel with other - instances of service enumeration of attempts to stop a service and then disable - it. Adversaries utilize this technique to terminate security services or other related - services to continue there objective and evade detections. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: afb31de4-d023-11eb-98d5-acde48001122 -known_false_positives: It is possible administrative scripts may start/stop/delete - services. Filter as needed. -name: Attempt To Disable Services -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. -search: '| from read_ssa_enriched_events() | eval _datamodels=ucast(map_get(input_event, - "_datamodels"), "collection", []), body={} | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%disabled%") AND like(cmd_line, "%config%") - AND process_name="sc.exe" | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 9 - - CIS 8 - confidence: 60 - context: - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Persistence - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log - impact: 60 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. - mitre_attack_id: - - T1489 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - risk_score: 36 - risk_severity: medium - security_domain: endpoint -test: - name: Attempt To Disable Services Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log - file_name: sc_disable.log - source: WinEventLog:Security - description: Test for usage of sc.exe to disable a service - file: endpoint/ssa___attempt_to_disable_services.yml - name: Attempt To Disable Services - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml b/dist/ssa/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml deleted file mode 100644 index cbc0646e7c..0000000000 --- a/dist/ssa/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Jose Hernandez, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -description: The following analytic identifies the use of `reg.exe` attempting to - export Windows registry keys that contain hashed credentials. Adversaries will utilize - this technique to capture and perform offline password cracking. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 14038953-e5f2-4daf-acff-5452062baf03 -known_false_positives: None identified. -name: Attempted Credential Dump From Registry via Reg exe -product: -- Splunk Behavioral Analytics -references: -- https://github.com/splunk/security_content/blob/55a17c65f9f56c2220000b62701765422b46125d/detections/attempted_credential_dump_from_registry_via_reg_exe.yml -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets -risk_message: An attempt to save registry keys storing credentials has been performed - on $dest_device_id$ by $dest_user_id$ via process $process_name$. -search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval process_name=lower(ucast(map_get(input_event, - "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name="cmd.exe" - OR process_name="reg.exe" | where cmd_line != null AND match_regex(cmd_line, /(?i)save\s+/)=true - AND ( match_regex(cmd_line, /(?i)HKLM\\Security/)=true OR match_regex(cmd_line, - /(?i)HKLM\\SAM/)=true OR match_regex(cmd_line, /(?i)HKLM\\System/)=true OR match_regex(cmd_line, - /(?i)HKEY_LOCAL_MACHINE\\Security/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\SAM/)=true - OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\System/)=true ) | eval start_time - = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) - | into write_ssa_detected_events(); ' -tags: - analytic_story: - - Credential Dumping - asset_type: Endpoint - cis20: - - CIS 3 - - CIS 5 - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: An attempt to save registry keys storing credentials has been performed - on $dest_device_id$ by $dest_user_id$ via process $process_name$. - mitre_attack_id: - - T1003 - - T1003.002 - nist: - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: process - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - - cmd_line - risk_score: 63 - risk_severity: low - security_domain: endpoint -test: - name: Attempted Credential Dump From Registry via Reg exe - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test credential dumping detections - file: endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml - name: Attempted Credential Dump From Registry via Reg exe - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___bcdedit_failure_recovery_modification.yml b/dist/ssa/detections/ssa___bcdedit_failure_recovery_modification.yml deleted file mode 100644 index a27a74f132..0000000000 --- a/dist/ssa/detections/ssa___bcdedit_failure_recovery_modification.yml +++ /dev/null @@ -1,99 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search looks for flags passed to bcdedit.exe modifications to the - built-in Windows error recovery boot configurations. This is typically used by ransomware - to prevent recovery. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13 -known_false_positives: Administrators may modify the boot configuration. -name: BCDEdit Failure Recovery Modification -product: -- Splunk Behavioral Analytics -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability - to recover the endpoint. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bcdedit.exe" - AND (like (cmd_line, "%recoveryenabled%") AND like (cmd_line, "%no%")) | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - Ryuk Ransomware - - Ransomware - cis20: - - CIS 8 - confidence: 80 - context: - - Source:Endpoint - - Stage:Impact - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - impact: 100 - kill_chain_phases: - - Actions on Objectives - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability - to recover the endpoint. - mitre_attack_id: - - T1490 - nist: - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: BCDEdit Failure Recovery Modification - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - description: Test detection of BCDEdit Failure Recovery Modification - file: endpoint/ssa___bcdedit_failure_recovery_modification.yml - name: BCDEdit Failure Recovery Modification - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml b/dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml deleted file mode 100644 index 889f60f282..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml +++ /dev/null @@ -1,100 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies the use of CacheDump with the `-s` parameter to dump cached - credentials on the associated endpoint. Adversaries use Cachedump as it is a publicly-available - tool that extracts cached password hashes from a system''s registry.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 312582f2-5e91-42c1-a275-cd67f31373c8 -known_false_positives: False positives will be limited as this analytic targets specific - credential dumping process names. Filter as needed. -name: Credential Extraction indicative of FGDump and CacheDump with s option -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/software/S0119/ -- https://en.kali.tools/all/?tool=182 -- http://foofus.net/goons/fizzgig/fgdump/ -- https://attack.mitre.org/software/S0120/ -risk_message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND process_name != null AND parent_process_name != null - AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, - /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true - AND match_regex(cmd_line, /(?i)\-s/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$. - mitre_attack_id: - - T1003 - - T1003.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml b/dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml deleted file mode 100644 index 2cb20aa5bd..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies the use of CacheDump with the `-v` parameter to dump cached - credentials on the associated endpoint. Adversaries use Cachedump as it is a publicly-available - tool that extracts cached password hashes from a system''s registry.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 -known_false_positives: False positives will be limited as this analytic targets specific - credential dumping process names. Filter as needed. -name: Credential Extraction indicative of FGDump and CacheDump with v option -product: -- Splunk Behavioral Analytics -references: [] -risk_message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, - /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true - AND match_regex(cmd_line, /(?i)\-v/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ - mitre_attack_id: - - T1003 - - T1003.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml b/dist/ssa/detections/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml deleted file mode 100644 index 4c2c36d0c0..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. LaZagne is a tool that extracts various kinds - of credentials from a local computer, including account passwords, domain passwords, - browser passwords, etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 341975fa-4ad0-4f01-9acc-df4f69742db7 -known_false_positives: None identified. -name: Credential Extraction indicative of Lazagne command line options -product: -- Splunk Behavioral Analytics -references: [] -risk_message: Lazagne malware is extracting/decoding encoded credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, - /(?i)all\s+\-oA\s+\-output/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Lazagne malware is extracting/decoding encoded credentials. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ - mitre_attack_id: - - T1003 - - T1555 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml b/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml deleted file mode 100644 index 8b64d2eba1..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies modules within DSInternals that are used for extracting credentials - from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, `ConvertFrom-GPPrefPassword`, - `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, - `ConvertTo-LMHash`, `ConvertTo-NTHash` `ConvertTo-OrgIdHash` or `ConvertTo-UnicodePassword`. - Adversaries may use these modules for decrypting or transforming the stored credentials.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Credential Extraction indicative of use of DSInternals credential conversion - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is converting stolen credential material to a form - applicable to authentications. Operation is performed on the device $dest_device_id$, - by the account $dest_user_id$ via process $process_name$. -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true - OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, - /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true - OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, - /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true - OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, - /(?i)ConvertTo-UnicodePassword/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is converting stolen credential material to a form - applicable to authentications. Operation is performed on the device $dest_device_id$, - by the account $dest_user_id$ via process $process_name$. - mitre_attack_id: - - T1003 - - T1003.002 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml b/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml deleted file mode 100644 index f45b2993b6..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies modules of DSInternals being used on the associated endpoint. - Adversaries may use these modules for manipulating data related to Active Directory - and credentials.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Credential Extraction indicative of use of DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is accessing sensitive credential material such - as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, - /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true - OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, - /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true - OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, - /(?i)Get-SamPasswordPolicy/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is accessing sensitive credential material such as - KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ - mitre_attack_id: - - T1003 - - T1003.002 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml b/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml deleted file mode 100644 index 152bedd309..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. Mimikatz is a collection of tools and modules - commonly employed in Windows exploits.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 -known_false_positives: None identified. -name: Credential Extraction indicative of use of Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is extracting/decoding encoded credentials from stores - such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true - OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true - OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true - OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true - OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 95 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is extracting/decoding encoded credentials from stores - such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 66 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml b/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml deleted file mode 100644 index e6a8ff148f..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. PowerSploit is a collection of Microsoft PowerShell - modules commonly employed in exploits.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 5f1186a4-e681-446e-851c-dc9574ad28eb -known_false_positives: None identified. -name: Credential Extraction indicative of use of PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is extracting encoded credentials or spoofing automated - logings. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true - OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true - OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, - /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true - OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, - /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is extracting encoded credentials or spoofing automated - logings. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml b/dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml deleted file mode 100644 index 82a297f80d..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml +++ /dev/null @@ -1,95 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, - livekd and windbg, can be leveraged to read credential material directly from memory - and process dumps.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c20bb8ec-e1b0-4640-b0ef-3a4c54f8c112 -known_false_positives: Although unlikely, using debuggers this way may be indicative - of developers analyzing crash dumps of their code. Note, even for developers this - is an unusual way of working on code - debuggers are mostly used to step through - code, not analyze its crash dumps. -name: Credential Extraction native Microsoft debuggers peek into the kernel -product: -- Splunk Behavioral Analytics -references: -- https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29 -risk_message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, by - the account $dest_user_id$ via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line != null AND parent_process_name != null AND process_name - != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, - /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true - AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml b/dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml deleted file mode 100644 index 2c56028283..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, - livekd and windbg, can be leveraged to read credential material directly from memory - and process dumps.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: adc51a77-90c9-4358-b43c-f10dd1a27d05 -known_false_positives: Although unlikely, using debuggers this way may be indicative - of developers analyzing crash dumps of their code. Note, even for developers this - is an unusual way of working on code - debuggers are mostly used to step through - code, not analyze its crash dumps. -name: Credential Extraction native Microsoft debuggers via z command line option -product: -- Splunk Behavioral Analytics -references: [] -risk_message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, by - the account $dest_user_id$ via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line != null AND process_name != null AND ( match_regex(process_name, - /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, - /(?i)\-z\s+/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml b/dist/ssa/detections/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml deleted file mode 100644 index 46f99c3fb1..0000000000 --- a/dist/ssa/detections/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml +++ /dev/null @@ -1,86 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. PowerSploit and DSInternals are common exploit - APIs offering PowerShell modules for various exploits of Windows and Active Directory - environments.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: e4f126b5-e6bc-4a5c-b1a8-d07bc6c4a49f -known_false_positives: None identified. -name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and - DSInternals -product: -- Splunk Behavioral Analytics -references: [] -risk_message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount - module. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, - /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\|]+/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount - module. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___delete_a_net_user.yml b/dist/ssa/detections/ssa___delete_a_net_user.yml deleted file mode 100644 index ba622e4b1c..0000000000 --- a/dist/ssa/detections/ssa___delete_a_net_user.yml +++ /dev/null @@ -1,109 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This analytic will detect a suspicious net.exe/net1.exe command-line - to delete a user on a system. This technique may be use by an administrator for - legitimate purposes, however this behavior has been used in the wild to impair some - user or deleting adversaries tracks created during its lateral movement additional - systems. During triage, review parallel processes for additional behavior. Identify - any other user accounts created before or after. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed net.exe may be used. -id: 8776d79c-d26e-11eb-9a56-acde48001122 -known_false_positives: System administrators or scripts may delete user accounts via - this technique. Filter as needed. -name: Delete A Net User -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user - account. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" - OR process_name="net.exe") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 4 - - CIS 16 - confidence: 70 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log - impact: 70 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user - account. - mitre_attack_id: - - T1531 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 49 - risk_severity: medium - security_domain: endpoint -test: - name: Delete A Net User Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log - file_name: net_user_del.log - source: WinEventLog:Security - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log - file_name: security.log - source: WinEventLog:Security - description: Test for usage of net.exe or net1.exe to delete net user - file: endpoint/ssa___delete_a_net_user.yml - name: Delete A Net User - pass_condition: '@count_gt(0)' -type: Anomaly -version: 3 diff --git a/dist/ssa/detections/ssa___deny_permission_using_cacls_utility.yml b/dist/ssa/detections/ssa___deny_permission_using_cacls_utility.yml deleted file mode 100644 index 82f434863b..0000000000 --- a/dist/ssa/detections/ssa___deny_permission_using_cacls_utility.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` - or `xcacls.exe` placing the deny permission on a file or directory. Adversaries - perform this behavior to prevent responders from reviewing or gaining access to - adversary files on disk. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. -id: b76eae28-cd25-11eb-9c92-acde48001122 -known_false_positives: System administrators may use cacls utilities but this is not - a common practice. Filter as needed. -name: Deny Permission using Cacls Utility -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to deny - a permission of a file or directory in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)deny/)=true - AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - cis20: - - CIS 14 - - CIS 16 - confidence: 70 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - impact: 50 - kill_chain_phases: - - Exploitation - message: A cacls process $process_name$ with commandline $cmd_line$ try to deny - a permission of a file or directory in host $dest_device_id$ - mitre_attack_id: - - T1222 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Deny Permission using Cacls Utility Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - file_name: all_icalc.log - source: WinEventLog:Security - description: Test for usage of cacls deny permission to a file(s) or folder(s) - file: endpoint/ssa___deny_permission_using_cacls_utility.yml - name: Deny Permission using Cacls Utility - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/dist/ssa/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml deleted file mode 100644 index e31f5ae16e..0000000000 --- a/dist/ssa/detections/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ /dev/null @@ -1,87 +0,0 @@ -author: Jose Hernandez, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -description: The following analytic identifies credential dumping using comsvcs.dll - with `regsvr32.exe`. This technique is common with adversaries who would like to - dump the memory of lsass.exe and perform offline password cracking. -how_to_implement: You must be ingesting endpoint data that tracks process activity, - including Windows command line logging. You can see how we test this with [Event - Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) - on the [attack_range](https://github.com/splunk/attack_range/blob/develop/ansible/roles/windows_common/tasks/windows-enable-4688-cmd-line-audit.yml). -id: 76bb9e35-f314-4c3d-a385-83c72a13ce4e -known_false_positives: False positives should be limited, filter as needed. -name: Detect Dump LSASS Memory using comsvcs -product: -- Splunk Behavioral Analytics -references: -- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll -risk_message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ - by user $dest_device_user$. -search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_event, - "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), - "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", - null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where process_name LIKE "%rundll32.exe%" AND match_regex(process, - /(?i)comsvcs.dll[,\s]+MiniDump/)=true | eval start_time = timestamp, end_time = - timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, - "process_name", process_name, "process", process]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Endpoint - cis20: - - CIS 8 - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ - by user $dest_device_user$. - mitre_attack_id: - - T1003.003 - - T1003 - nist: - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _tenant - - _time - - dest_device_id - - process - risk_score: 70 - risk_severity: low - security_domain: endpoint -test: - name: Detect Dump LSASS Memory using comsvcs - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test credential dumping detections - file: endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml - name: Detect Dump LSASS Memory using comsvcs - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___detect_kerberoasting.yml b/dist/ssa/detections/ssa___detect_kerberoasting.yml deleted file mode 100644 index 0d07185006..0000000000 --- a/dist/ssa/detections/ssa___detect_kerberoasting.yml +++ /dev/null @@ -1,94 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: -- Certificates -date: '2020-10-21' -description: This search detects a potential kerberoasting attack via service principal - name requests -how_to_implement: The test data is converted from Windows Security Event logs generated - from Attach Range simulation and used in SPL search and extended to SPL2 -id: dabdd6d7-3e10-42be-8711-4e124f7a3850 -known_false_positives: Older systems that support kerberos RC4 by default NetApp may - generate false positives -name: Detect Kerberoasting -product: -- Splunk Behavioral Analytics -references: -- Initial ESCU implementation by Jose Hernandez and Patrick Bareiss -risk_message: Kerberoasting malware is potentially applying stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), - EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, - "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), - ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, - "service_id"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where EventCode="4769" - AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" | first_time_event - input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] - | where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID - | eval start_time=_time, end_time=_time | eval body=create_map(["event_id", event_id, - "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, - "TicketEncryptionType", TicketEncryptionType]), entities = mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | select start_time, end_time, entities, body | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - cis20: - - CIS 8 - - CIS 16 - confidence: 20 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Kerberoasting malware is potentially applying stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1558.003 - - T1558 - nist: - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - service_name - - _time - - event_code - - ticket_encryption_type - - service_id - - ticket_options - risk_score: 14 - risk_severity: medium - security_domain: endpoint -test: - name: Detect Kerberoasting - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test detection of kerberoasting - file: endpoint/ssa___detect_kerberoasting.yml - name: Detect kerberoasting - pass_condition: '@count_eq(0)' -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___detect_pass_the_hash.yml b/dist/ssa/detections/ssa___detect_pass_the_hash.yml deleted file mode 100644 index 54ff68c628..0000000000 --- a/dist/ssa/detections/ssa___detect_pass_the_hash.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: -- Authentication -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This search - looks for specific authentication events from the Windows Security Event logs to - detect potential attempts using Pass-the-Hash technique.' -how_to_implement: The test data is converted from Windows Security Event logs generated - from Attach Range simulation and used in SPL search and extended to SPL2 -id: 7cd8b9fa-6b0c-424f-92a6-9c5287a72f5f -known_false_positives: Legitimate logon activity by authorized NTLM systems may be - detected by this search. Please investigate as appropriate. -name: Detect Pass the Hash -product: -- Splunk Behavioral Analytics -references: -- Initial ESCU implementation by Bhavin Patel and Patrick Bareiss -risk_message: Potential use of the pass the hash/token attacks that spoof authentication. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) - | eval signature_id=map_get(input_event, "signature_id"), authentication_type=map_get(input_event, - "authentication_type"), authentication_method=map_get(input_event, "authentication_method"), - origin_device_domain=map_get(input_event, "origin_device_domain"), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - - | where (authentication_type="3" AND authentication_method="NtLmSsp") OR (authentication_type="9" - AND authentication_method="seclogo") - - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "authentication_type", authentication_type, - "authentication_method", authentication_method]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Lateral Movement - cis20: - - CIS 3 - - CIS 5 - - CIS 16 - confidence: 20 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Potential use of the pass the hash/token attacks that spoof authentication. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1550 - - T1550.002 - nist: - - PR.PT - - PR.AT - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - signature_id - - authentication_type - - _time - - authentication_method - - origin_device_domain - - dest_user_id - - dest_device_id - risk_score: 16 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___detect_prohibited_applications_spawning_cmd_exe.yml b/dist/ssa/detections/ssa___detect_prohibited_applications_spawning_cmd_exe.yml deleted file mode 100644 index f369662145..0000000000 --- a/dist/ssa/detections/ssa___detect_prohibited_applications_spawning_cmd_exe.yml +++ /dev/null @@ -1,103 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-10' -description: The following analytic identifies parent processes, browsers, Windows - terminal applications, Office Products and Java spawning cmd.exe. By its very nature, - many applications spawn cmd.exe natively or built into macros. Much of this will - need to be tuned to further enhance the risk. -how_to_implement: In order to successfully implement this analytic, you will need - endpoint process data from a EDR product or Sysmon. This search has been modified - to process raw sysmon data from attack_range's nxlogs on DSP. -id: c10a18cb-fd80-4ffa-a844-25026e0a0c94 -known_false_positives: There are circumstances where an application may legitimately - execute and interact with the Windows command-line interface. -name: Detect Prohibited Applications Spawning cmd exe -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1059/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event - that warrants investigating. -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) - | eval process_name=ucast(map_get(input_event, "process_name"), "string", null), - parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", - null)), cmd_line=lower(ucast(map_get(input_event, "process"),"string", null)), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event,"event_id"), "string", null) - | where process_name="cmd.exe" | rex field=parent_process "(?[^\\\\]+)$" - | where ParentBaseFileName="winword.exe" OR ParentBaseFileName="excel.exe" OR ParentBaseFileName="outlook.exe" - OR ParentBaseFileName="powerpnt.exe" OR ParentBaseFileName="visio.exe" OR ParentBaseFileName="mspub.exe" - OR ParentBaseFileName="acrobat.exe" OR ParentBaseFileName="acrord32.exe" OR ParentBaseFileName="iexplore.exe" - OR ParentBaseFileName="opera.exe" OR ParentBaseFileName="firefox.exe" OR (ParentBaseFileName="java.exe" - AND (cmd_line IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%patch1-Hotfix1a%")))) - OR ParentBaseFileName="powershell.exe" OR (ParentBaseFileName="chrome.exe" AND (cmd_line - IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%chrome-extension%")))) - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "process_name", process_name, - "parent_process_name", parent_process, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Suspicious Command-Line Executions - cis20: - - CIS 8 - confidence: 50 - context: - - Source:Endpoint - - Stage:Defense Evasion - impact: 70 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event - that warrants investigating. - mitre_attack_id: - - T1059 - nist: - - PR.PT - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Detect Prohibited Applications Spawning cmd exe Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Detect Prohibited Applications Spawning cmd exe - file: endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml - name: Detect Prohibited Applications Spawning cmd exe - pass_condition: '@count_gt(0)' -type: Anomaly -version: 2 diff --git a/dist/ssa/detections/ssa___detect_rclone_command-line_usage.yml b/dist/ssa/detections/ssa___detect_rclone_command-line_usage.yml deleted file mode 100644 index effffe33fc..0000000000 --- a/dist/ssa/detections/ssa___detect_rclone_command-line_usage.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-03' -description: This analytic identifies commonly used command-line arguments used by - `rclone.exe` to initiate a file transfer. Some arguments were negated as they are - specific to the configuration used by adversaries. In particular, an adversary may - list the files or directories of the remote file share using `ls` or `lsd`, which - is not indicative of malicious behavior. During triage, at this stage of a ransomware - event, exfiltration is about to occur or has already. Isolate the endpoint and continue - investigating by review file modifications and parallel processes. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: e8b74268-5454-11ec-a799-acde48001122 -known_false_positives: False positives should be limited as this is restricted to - the Rclone process name. Filter or tune the analytic as needed. -name: Detect RClone Command-Line Usage -product: -- Splunk Behavioral Analytics -references: -- https://redcanary.com/blog/rclone-mega-extortion/ -- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html -- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ -- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a remote - cloud service to move files or folders. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="rclone.exe" - AND (like (cmd_line, "%copy%") OR like (cmd_line, "%mega%")OR like (cmd_line, "%pcloud%") - OR like (cmd_line, "%ftp%") OR like (cmd_line, "%--config%") OR like (cmd_line, - "%--progress%") OR like (cmd_line, "%--no-check-certificate%") OR like (cmd_line, - "%--ignore-existing%") OR like (cmd_line, "%--auto-confirm%") OR like (cmd_line, - "%--transfers%") OR like (cmd_line, "%--multi-thread-streams%")) | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) - | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - DarkSide Ransomware - - Ransomware - automated_detection_testing: passed - confidence: 70 - context: - - Source:Endpoint - - Stage:Exfiltration - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log - impact: 50 - kill_chain_phases: - - Exfiltration - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a - remote cloud service to move files or folders. - mitre_attack_id: - - T1020 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___disable_net_user_account.yml b/dist/ssa/detections/ssa___disable_net_user_account.yml deleted file mode 100644 index 6e179bef39..0000000000 --- a/dist/ssa/detections/ssa___disable_net_user_account.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This analytic will identify a suspicious command-line that disables a - user account using the native `net.exe` or `net1.exe` utility to Windows. This technique - may used by the adversaries to interrupt availability of accounts and continue the - impact against the organization. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be - used. -id: ba858b08-d26c-11eb-af9b-acde48001122 -known_false_positives: System administrators or automated scripts may disable an account - but not a common practice. Filter as needed. -name: Disable Net User Account -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND like(cmd_line, "%user%") - AND (process_name="net1.exe" OR process_name="net.exe") | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 4 - - CIS 16 - confidence: 70 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log - impact: 70 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. - mitre_attack_id: - - T1489 - - T1078 - nist: - - PR.AC - - PR.IP - observable: - - name: user - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 49 - risk_severity: medium - security_domain: endpoint -test: - name: Disable Net User Account Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log - file_name: net_user_dis.log - source: WinEventLog:Security - description: Test for usage of net.exe or net1.exe to disable net user - file: endpoint/ssa___disable_net_user_account.yml - name: Disable Net User Account - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/detections/ssa___dns_exfiltration_using_nslookup_app.yml b/dist/ssa/detections/ssa___dns_exfiltration_using_nslookup_app.yml deleted file mode 100644 index 0f154fa153..0000000000 --- a/dist/ssa/detections/ssa___dns_exfiltration_using_nslookup_app.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search is to detect potential DNS exfiltration using nslookup application. - This technique are seen in couple of malware and APT group to exfiltrated collected - data in a infected machine or infected network. This detection is looking for unique - use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are - commonly used by attacker and also the retry parameter which is designed to query - C2 DNS multiple tries. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: 2452e632-9e0d-11eb-34ba-acde48001122 -known_false_positives: It is possible for some legitimate administrative utilities - to use similar cmd_line parameters. Filter as needed. -name: DNS Exfiltration Using Nslookup App -product: -- Splunk Behavioral Analytics -references: -- https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html -- https://www.varonis.com/blog/dns-tunneling/ -- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related - to DNS exfiltration. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="nslookup.exe" - AND (like (cmd_line, "%-querytype=%") OR like (cmd_line, "%-qt=%") OR like (cmd_line, - "%-q=%") OR like (cmd_line, "%-type=%") OR like (cmd_line, "%-retry=%")) | eval - start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, - "process_name", process_name, "parent_process_name", parent_process_name, "process_path", - process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Suspicious DNS Traffic - - Dynamic DNS - - Command and Control - - Data Exfiltration - automated_detection_testing: passed - confidence: 80 - context: - - Source:Endpoint - - Stage:Exfiltration - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log - impact: 90 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related - to DNS exfiltration. - mitre_attack_id: - - T1048 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 72 - risk_severity: low - security_domain: endpoint -test: - name: DNS Exfiltration Using Nslookup App Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - file: endpoint/ssa_dns_exfiltration_using_nslookup_app.yml - name: DNS Exfiltration Using Nslookup App - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___excessive_number_of_office_files_copied.yml b/dist/ssa/detections/ssa___excessive_number_of_office_files_copied.yml deleted file mode 100644 index 8a239045f5..0000000000 --- a/dist/ssa/detections/ssa___excessive_number_of_office_files_copied.yml +++ /dev/null @@ -1,64 +0,0 @@ -author: Patrick Bareiss, Splunk -datamodel: -- Endpoint_Filesystem -date: '2021-12-07' -description: This detection detects a high amount of office file copied. This can - be an indicator for a malicious insider. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Filesytem` node. -id: 3c6594a9-8df6-45a1-9357-d73b62083c63 -known_false_positives: user may copy a lot of office fies from one folder to another -name: Excessive Number of Office Files Copied -product: -- Splunk Behavioral Analytics -references: [] -risk_message: High number of files copied -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", - null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, - "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) - | where "Endpoint_Filesystem" IN(_datamodels) | where action="created" | where like(file_name, - "%.doc%") OR like(file_name, "%.xls%") OR like(file_name, "%.ppt%") | stats count(file_name) - AS count BY dest_user_id, dest_device_id, span(timestamp, 10m) | where count > 20 - | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, - dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' -tags: - analytic_story: [] - confidence: 80 - context: - - Source:Endpoint - - Stage:Exfitration - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log - impact: 90 - kill_chain_phases: - - Exploitation - message: High number of files copied - mitre_attack_id: - - T1048.003 - product: - - Splunk Behavioral Analytics - required_fields: - - action - - process - - file_name - - file_path - risk_score: 72 - risk_severity: low - security_domain: endpoint -test: - name: Excessive Number of Office Files Copied Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log - file_name: sysmon.log - source: xmlwineventlog - description: Test for Excessive Number of Office Files Copied - file: endpoint/ssa___excessive_number_of_office_files_copied.yml - name: Excessive Number of Office Files Copied - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/detections/ssa___first_time_seen_command_line_argument.yml b/dist/ssa/detections/ssa___first_time_seen_command_line_argument.yml deleted file mode 100644 index 5bed7361d2..0000000000 --- a/dist/ssa/detections/ssa___first_time_seen_command_line_argument.yml +++ /dev/null @@ -1,89 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This search looks for command-line arguments that use a `/c` parameter - to execute a command that has not previously been seen. This is an implementation - on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following - analytic identifies first time seen command-line arguments on a single endpoint. - The analytic looks for arguments instantiated by `cmd.exe /c` and the associated - command-line. Adversaries automate or spawn multiple processes using this method, - this analytic may assist with identifying the first time it's been found on this - endpoint.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 -known_false_positives: Legitimate programs use command-line arguments to execute. - Verify the command-line arguments to check what command/program is being executed. - Filtering will be needed. -name: First time seen command line argument -product: -- Splunk Behavioral Analytics -references: [] -risk_message: A process $process_name$ ha been identified in the environment with - a command-line $cmd_line$ not previously seen before on host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), - "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), - cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, - "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, - "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" - */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, "\\PATH"), - /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, - /\d+/, "N"), event_id=ucast(map_get(input_event, "event_id"), "string", null) | - where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* - \/[cC] .*/)=true | select process_name, cmd_line, cmd_line_norm, timestamp, dest_device_id, - dest_user_id | first_time_event input_columns=["cmd_line_norm"] | where first_time_cmd_line_norm - | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 3 - - CIS 8 - confidence: 60 - context: - - source:endpoint - - stage: Defense Evasion - impact: 50 - kill_chain_phases: - - Command and Control - - Actions on Objectives - message: A process $process_name$ ha been identified in the environment with a command-line - $cmd_line$ not previously seen before on host $dest_device_id$ - mitre_attack_id: - - T1059 - - T1202 - nist: - - PR.PT - - DE.CM - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - - cmd_line - risk_score: 30 - risk_severity: medium - security_domain: endpoint -type: Anomaly -version: 4 diff --git a/dist/ssa/detections/ssa___fsutil_zeroing_file.yml b/dist/ssa/detections/ssa___fsutil_zeroing_file.yml deleted file mode 100644 index 0efb8d94cc..0000000000 --- a/dist/ssa/detections/ssa___fsutil_zeroing_file.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search is to detect a suspicious fsutil process to zeroing a target - file. This technique was seen in lockbit ransomware where it tries to zero out its - malware path as part of its defense evasion after encrypting the compromised host. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed net.exe may be used. -id: f792cdc9-43ee-4429-a3c0-ffce4fed1a85 -known_false_positives: System administrators or scripts may delete user accounts via - this technique. Filter as needed. -name: Fsutil Zeroing File -product: -- Splunk Behavioral Analytics -references: -- https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/ -- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file deletion. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" - AND (like (cmd_line, "%setzerodata%")) | eval start_time=timestamp, end_time=timestamp, - entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, - "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", - cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, - "process_path", process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Ransomware - confidence: 90 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: [] - impact: 60 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file - deletion. - mitre_attack_id: - - T1070 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 54 - risk_severity: low - security_domain: endpoint -test: - name: FSUtil Zeroing File - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - description: Test detection of FSUtil Zeroing File - file: endpoint/ssa___fsutil_zeroing_file.yml - name: FSUtil Zeroing File - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___grant_permission_using_cacls_utility.yml b/dist/ssa/detections/ssa___grant_permission_using_cacls_utility.yml deleted file mode 100644 index 70f10dafc1..0000000000 --- a/dist/ssa/detections/ssa___grant_permission_using_cacls_utility.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` - or `xcacls.exe` placing the grant permission on a file or directory. Adversaries - perform this behavior to allow components of their files to run, however it allows - responders to review or gaining access to adversary files on disk. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. -id: c6da561a-cd29-11eb-ae65-acde48001122 -known_false_positives: System administrators may use cacls utilities but this is not - a common practice. Filter as needed. -name: Grant Permission Using Cacls Utility -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to grant - user a permission to a file or directory in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)grant/)=true - AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - cis20: - - CIS 14 - - CIS 16 - confidence: 70 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - impact: 50 - kill_chain_phases: - - Exploitation - message: A cacls process $process_name$ with commandline $cmd_line$ try to grant - user a permission to a file or directory in host $dest_device_id$ - mitre_attack_id: - - T1222 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Grant Permission Using Cacls Utility Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - file_name: all_icalc.log - source: WinEventLog:Security - description: Test for usage of cacls grant permission to a file(s) or folder(s) - file: endpoint/ssa___grant_permission_using_cacls_utility.yml - name: Grant Permission Using Cacls Utility - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/detections/ssa___high_file_deletion_frequency.yml b/dist/ssa/detections/ssa___high_file_deletion_frequency.yml deleted file mode 100644 index d8d355b0a6..0000000000 --- a/dist/ssa/detections/ssa___high_file_deletion_frequency.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Patrick Bareiss, Splunk -datamodel: -- Endpoint_Filesystem -date: '2021-12-07' -description: This detection detects a high amount of file deletions in a short time - for specific file types. This can be an indicator for a malicious insider. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Filesytem` node. -id: b6200efd-13bd-4336-920a-057b25bbcfaf -known_false_positives: user may delete bunch of pictures or files in a folder. -name: High File Deletion Frequency -product: -- Splunk Behavioral Analytics -references: -- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html -- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html -risk_message: High frequency file deletion activity detected on host $Computer$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", - null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, - "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) - | where "Endpoint_Filesystem" IN(_datamodels) | where action="deleted" | where like(file_name, - "%.cmd") OR like(file_name, "%.ini") OR like(file_name, "%.gif") OR like(file_name, - "%.jpg") OR like(file_name, "%.jpeg") OR like(file_name, "%.db") OR like(file_name, - "%.doc%") OR like(file_name, "%.ps1") OR like(file_name, "%.xls%") OR like(file_name, - "%.ppt%") OR like(file_name, "%.bmp") OR like(file_name, "%.zip") OR like(file_name, - "%.rar") OR like(file_name, "%.7z") OR like(file_name, "%.chm") OR like(file_name, - "%.png") OR like(file_name, "%.log") OR like(file_name, "%.vbs") OR like(file_name, - "%.js") | stats count(file_name) AS count BY dest_user_id, dest_device_id, span(timestamp, - 10m) | where count > 20 | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, - dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Clop Ransomware - confidence: 80 - context: - - Source:Endpoint - - Stage:Execution - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log - impact: 90 - kill_chain_phases: - - Exploitation - message: High frequency file deletion activity detected on host $Computer$ - mitre_attack_id: - - T1485 - observable: - - name: user - role: - - Victim - type: User - - name: Computer - role: - - Victim - type: Endpoint - - name: deleted_files - role: - - Target - type: File Name - product: - - Splunk Behavioral Analytics - required_fields: - - action - - process - - file_name - - file_path - risk_score: 72 - risk_severity: low - security_domain: endpoint -test: - name: High File Deletion Frequency Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log - file_name: sysmon.log - source: xmlwineventlog - description: Test for High File Deletion Frequency - file: endpoint/ssa___high_file_deletion_frequency.yml - name: High File Deletion Frequency - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_access_to_user_content_via_powersploit_modules.yml b/dist/ssa/detections/ssa___illegal_access_to_user_content_via_powersploit_modules.yml deleted file mode 100644 index 341dc81365..0000000000 --- a/dist/ssa/detections/ssa___illegal_access_to_user_content_via_powersploit_modules.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegaly access user content, - such as key logging, audio recording, screenshots, tapping into http and RDP sessions, - etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 01fc7d91-eb0c-478e-8633-e4fa4904463a -known_false_positives: None identified. -name: Illegal Access To User Content via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is tapping into user content - microphone, camera, - ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR - match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true - OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, - /(?i)Get-WebConfig/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Exfiltration - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log - impact: 85 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is tapping into user content - microphone, camera, - ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1021 - - T1113 - - T1123 - - T1563 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 85 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_account_creation_via_powersploit_modules.yml b/dist/ssa/detections/ssa___illegal_account_creation_via_powersploit_modules.yml deleted file mode 100644 index 97237df015..0000000000 --- a/dist/ssa/detections/ssa___illegal_account_creation_via_powersploit_modules.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that create accounts illegaly.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 20fba62a-fa5b-46cc-b39f-473fa248fee2 -known_false_positives: None identified. -name: Illegal Account Creation via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is creating illegal domain accounts. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)New-DomainUser/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Persistence - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is creating illegal domain accounts. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1585 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Account Creation via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal account creation detections - file: endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml - name: Illegal Account Creation via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml deleted file mode 100644 index aa16051c53..0000000000 --- a/dist/ssa/detections/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml +++ /dev/null @@ -1,83 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that delete event logs.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b -known_false_positives: None identified. -name: Illegal Deletion of Logs via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is deleting event logs to cover tracks of malicious - activity. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Log Manipulation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is deleting event logs to cover tracks of malicious activity. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1070 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml b/dist/ssa/detections/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml deleted file mode 100644 index 4d6a3d0141..0000000000 --- a/dist/ssa/detections/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of DSInternals modules that enable or disable accounts illegaly.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 3e0f9962-9989-445f-878c-939443326b63 -known_false_positives: None identified. -name: Illegal Enabling or Disabling of Accounts via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is illegally enabling or disabling accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is illegally enabling or disabling accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml b/dist/ssa/detections/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml deleted file mode 100644 index 0b45aa84ef..0000000000 --- a/dist/ssa/detections/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml +++ /dev/null @@ -1,89 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of DSInternals modules for illegal management of Active Directoty - elements and policies.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: a587ca9f-c138-47b4-ba51-699f319b8cc5 -known_false_positives: None identified. -name: Illegal Management of Active Directory Elements and Policies via DSInternals - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is controlling infrastructure by modifying Active - Directory elements, domain controllers, and policies. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true - OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, - /(?i)Set-LsaPolicyInformation/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is controlling infrastructure by modifying Active Directory - elements, domain controllers, and policies. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1098 - - T1207 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml b/dist/ssa/detections/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml deleted file mode 100644 index 12c1053ff5..0000000000 --- a/dist/ssa/detections/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegal management of computers - and Active Directory elements.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 75760c11-7d48-4968-b828-013b299e8f6d -known_false_positives: None identified. -name: Illegal Management of Computers and Active Directory Elements via PowerSploit - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is controlling infrastructure by modifying Active - Directory elements or local Master Boot Records. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR - match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, - /(?i)Set-MasterBootRecord/)=true ) - - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is controlling infrastructure by modifying Active Directory - elements or local Master Boot Records. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1098 - - T1207 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/dist/ssa/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml deleted file mode 100644 index 6ec2973e83..0000000000 --- a/dist/ssa/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that illegaly elevate general privileges - or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent - WMI, access to OS objects under desired identities.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 88c10ee9-fe72-4bce-b343-5b129044b991 -known_false_positives: None identified. -name: Illegal Privilege Elevation and Persistence via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is planting attack persistence elements, altering - privileges and access controls. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true - OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true - OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Malicious PowerShell - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Command And Control - - Stage:Persistence - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is planting attack persistence elements, altering privileges - and access controls. Operation is performed at the device $dest_device_id$, by - the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1053 - - T1134 - - T1548 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Privilege Elevation and Persistence via PowerSploit modules - SSA - Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test privilege elevation and persistence detections - file: endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml - name: Illegal Privilege Elevation and Persistence via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml deleted file mode 100644 index 14b98b6333..0000000000 --- a/dist/ssa/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for illegal privilege elevation.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 2f873b1f-6352-4844-b7b9-b419f09a42c7 -known_false_positives: None identified. -name: Illegal Privilege Elevation via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is setting highest privileges to malicious entities. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Privilege Escalation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is setting highest privileges to malicious entities. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1134 - - T1548 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Privilege Elevation via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal privilege elevation detections - file: endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml - name: Illegal Privilege Elevation via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml deleted file mode 100644 index 65e6678eaa..0000000000 --- a/dist/ssa/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml +++ /dev/null @@ -1,100 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for illegal control over services and processes, - including the authentication service.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: aaf3adf1-73e1-4477-b4ee-3771898964f1 -known_false_positives: None identified. -name: Illegal Service and Process Control via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, - /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, - /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true - OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Service Abuse - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is controlling computer's processess and services. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1106 - - T1569 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Service and Process Control via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal service and process control detections - file: endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml - name: Illegal Service and Process Control via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/dist/ssa/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml deleted file mode 100644 index 6766a7231c..0000000000 --- a/dist/ssa/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml +++ /dev/null @@ -1,110 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegal control of services - and processes, such as installing or spoofing of malicious services, injecting malicious - code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to - service objects, etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 0e910e5b-309d-4bc3-8af2-0030c02aa353 -known_false_positives: None identified. -name: Illegal Service and Process Control via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true - OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, - /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true - OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, - /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true - OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, - /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true - OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, - /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true - ) - - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Service Abuse - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1055 - - T1106 - - T1569 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal service and process control detections - file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml - name: Illegal Service and Process Control via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___modify_acls_permission_of_files_or_folders.yml b/dist/ssa/detections/ssa___modify_acls_permission_of_files_or_folders.yml deleted file mode 100644 index ae2e490edf..0000000000 --- a/dist/ssa/detections/ssa___modify_acls_permission_of_files_or_folders.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This analytic identifies suspicious modification of ACL permission to - a files or folder to make it available to everyone or to a specific user. This technique - may be used by the adversary to evade ACLs or protected files access. This changes - is commonly configured by the file or directory owner with appropriate permission. - This behavior raises suspicion if this command is seen on an endpoint utilized by - an account with no permission to do so. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. -id: 9ae9a48a-cdbe-11eb-875a-acde48001122 -known_false_positives: System administrators may use this windows utility. filter - is needed. -name: Modify ACLs Permission Of Files Or Folders -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to modify - a permission of a file or directory in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND like(cmd_line, "%/G%") AND (match_regex(cmd_line, - /(?i)everyone:/)=true OR match_regex(cmd_line, /(?i)SYSTEM:/)=true) AND (process_name="cacls.exe" - OR process_name="xcacls.exe" OR process_name="icacls.exe") | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - cis20: - - CIS 8 - - CIS 13 - confidence: 70 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - impact: 50 - kill_chain_phases: - - Exploitation - message: A cacls process $process_name$ with commandline $cmd_line$ try to modify - a permission of a file or directory in host $dest_device_id$ - mitre_attack_id: - - T1222 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Modify ACLs Permission Of Files Or Folders Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - file_name: all_icalc.log - source: WinEventLog:Security - description: Test for modifying permission of a file(s) or folder(s) using cacls - utility. - file: endpoint/ssa___modify_acls_permission_of_files_or_folders.yml - name: Modify ACLs Permission Of Files Or Folders - pass_condition: '@count_gt(0)' -type: Anomaly -version: 2 diff --git a/dist/ssa/detections/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml b/dist/ssa/detections/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml deleted file mode 100644 index 5995bc4c02..0000000000 --- a/dist/ssa/detections/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml +++ /dev/null @@ -1,95 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-08-25' -description: Attacker activity may compromise executing several LOLBAS applications - in conjunction to accomplish their objectives. We are looking for more than usual - LOLBAS applications over a window of time, by building profiles per machine. -how_to_implement: Collect endpoint data such as sysmon or 4688 events. -id: 59c0dd70-169c-4900-9a1f-bfcf13302f93 -known_false_positives: 'Some administrative tasks may involve multiple use of LOLBAS - applications in a short period of time. This might trigger false positives at the - beginning when it hasn''t collected yet enough data to construct the baseline. - - ' -name: More than usual number of LOLBAS applications in short time period -product: -- Splunk Behavioral Analytics -references: -- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -risk_message: A system process $process_name$ with commandline $cmd_line$ spawn iin - short period of time in host $dest_device_id$ -search: ' | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, - "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, - "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | where process_name=="regsvcs.exe" OR process_name=="ftp.exe" - OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" - OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" - OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" - OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" - OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" - OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" - OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" - OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" - OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" - OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" - OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" - OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" - OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" - OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" - OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" - OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" - OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" - OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" - OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" - OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR - process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" - OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" - OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" - OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" - OR process_name=="msconfig.exe" | stats count(process_name) as lolbas_counter by - device,span(timestamp, 300s) | eval lolbas_counter=lolbas_counter*1.0 | rename window_end - as timestamp | adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" - window=2419200000L | where label AND quantile>0.99 | eval start_time = window_start, - end_time = timestamp, entities = mvappend(device), body=create_map(["lolbas_counter", - lolbas_counter, "quantile", quantile, "device", device]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - confidence: 50 - context: - - source:endpoint - - stage: Defense Evasion - impact: 50 - kill_chain_phases: - - Exploitation - message: A system process $process_name$ with commandline $cmd_line$ spawn iin short - period of time in host $dest_device_id$ - mitre_attack_id: - - T1059 - - T1053 - nist: - - PR.PT - - DE.CM - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - _time - - process_name - risk_score: 25 - risk_severity: medium - security_domain: endpoint -type: Anomaly -version: 2 diff --git a/dist/ssa/detections/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml b/dist/ssa/detections/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml deleted file mode 100644 index c1f2707376..0000000000 --- a/dist/ssa/detections/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml +++ /dev/null @@ -1,62 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: [] -date: '2020-08-25' -description: Malicious mails can conduct phishing that induces readers to open attachment, - click links or trigger third party service. This detect uses Natural Language Processing - (NLP) approach to analyze an email message's content (Sender, Subject and Body) - and judge whether it is a phishing email. The detection adopts a deep learning (neural - network) model that employs character level embeddings plus LSTM layers to perform - classification. The model is pre-trained and then published as ONNX format. Current - sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json - User are expected to re-train the model by combining with their own training data - for better accuracy using the provided model file (SMLE notebook). DSP pipeline - then processes the email message and passes it as an event to Apply ML Models function, - which returns the probability of a phishing email. Current implementation assumes - the email is fed to DSP in JSON format contains at least email's sender, subject - and its message body, including reply content, if any. -how_to_implement: Events are fed to DSP contains at least email's sender, subject - and its message body. -id: 4b237388-dfa1-41a6-91d4-4de2d598376f -known_false_positives: Because of imbalance of anomaly data in training, the model - will less likely report false positive. Instead, the model is more prone to false - negative. Current best recall score is ~85% -name: Phishing Email Detection by Machine Learning Method - SSA -product: -- Splunk Behavioral Analytics -references: [] -search: '| from read_ssa_enriched_events() | eval eventLine=concat(ucast(map_get(input_event, - "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " - "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), - _time=map_get(input_event, "_time") | where eventLine IS NOT NULL | eval mapC={" - ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, - ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, - "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, - ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, - "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, - "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, - "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, - "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": - 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": - 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": - 119, "x": 120, "y": 121, "z": 122, "{": 123, "|": 124, "}": 125, "~": 126}, ml_in - = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, - 1)), "float") ) | apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" - path="s3://smle-experiments/models/phishing_email" | eval probability = mvindex(ml_out, - 0) | where probability > 0.5 | eval start_time=_time, end_time=_time, entities="TBD", - body="TBD" | select probability, body, entities, start_time, end_time | into write_ssa_detected_events();' -tags: - cis20: - - CIS 8 - kill_chain_phases: - - Actions on Objectives - mitre_attack_id: - - T1566 - nist: - - PR.PT - - DE.CM - product: - - Splunk Behavioral Analytics - risk_severity: low - security_domain: mail server -type: Anomaly -version: 1 diff --git a/dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml b/dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml deleted file mode 100644 index e1415eadc5..0000000000 --- a/dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml +++ /dev/null @@ -1,102 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Authentication -date: '2021-11-30' -description: This detection identifies potential Pass the Token or Pass the Hash credential - stealing. We detect the main side effect of these attacks, which is a transition - from the dominant Kerberos logins to rare NTLM logins for a given user, as reported - by a detination device. -how_to_implement: You must be ingesting Windows Security logs from endpoint devices, - i.e., destinations of interest. Please make sure that event ID 4624 is being logged. -id: 82e76b80-5cdb-4899-9b43-85dbe777b36d -known_false_positives: Environments in which NTLM is used extremely rarely and for - benign purposes (such as a rare use of SMB shares). -name: Potential Pass the Token or Hash Observed at the Destination Device -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1550/002/ -- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ -risk_message: Potential lateral movement and credential stealing via Pass the Token - or Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the destination device $dest_device_id$ -search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", - null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), - dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), - signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), - authentication_method= lower(ucast(map_get(input_event, "authentication_method"), - "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) - - | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") - AND dest_user_id != null AND dest_device_id != null - - | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method - == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - - | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as - startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as - endNTLMTime by dest_user_id, dest_user, dest_device_id, span(timestamp, 86400s) - - | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND - (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - - | eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, - "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["event_id", - event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", - startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", - endNTLMTime]) - - | into write_ssa_detected_events();' -tags: - analytic_story: - - Active Directory Lateral Movement - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Stage:Lateral Movement - impact: 80 - kill_chain_phases: - - Lateral Movement - message: Potential lateral movement and credential stealing via Pass the Token or - Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the destination device $dest_device_id$ - mitre_attack_id: - - T1550 - - T1550.002 - nist: - - PR.PT - - PR.AT - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Other - type: Hostname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - signature_id - - dest_user - - dest_user_id - - dest_device_id - - authentication_method - risk_score: 72 - risk_severity: low - security_domain: endpoint -type: TTP -version: 3 diff --git a/dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml b/dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml deleted file mode 100644 index 74810e4d36..0000000000 --- a/dist/ssa/detections/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml +++ /dev/null @@ -1,103 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Authentication -date: '2021-11-05' -description: This detection identifies potential Pass the Token or Pass the Hash credential - stealing. We detect the main side effect of these attacks, which is a transition - from the dominant Kerberos logins to rare NTLM logins for a given user, as reported - by an event-collecting device (i.e., a specific domain controller or an endpoint - destination). -how_to_implement: You must be ingesting Windows Security logs from devices of interest - - at least from domain controllers. Please make sure that event ID 4624 is being - logged. -id: 1058ba3e-a698-49bc-a1e5-7cedece4ea87 -known_false_positives: Environments in which NTLM is used extremely rarely and for - benign purposes (such as a rare use of SMB shares). -name: Potential Pass the Token or Hash Observed by an Event Collecting Device -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1550/002/ -- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ -risk_message: Potential lateral movement and credential stealing via Pass the Token - or Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the logging device $origin_device_id$ -search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), - "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", - null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", - null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", - null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), - "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") - AND dest_user_id != null AND origin_device_id != null - - | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method - == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - - | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as - startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as - endNTLMTime by dest_user_id, dest_user, origin_device_id, span(timestamp, 86400s) - - | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND - (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - - | eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, - origin_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, - "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", - endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) - - | into write_ssa_detected_events();' -tags: - analytic_story: - - Active Directory Lateral Movement - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 80 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Stage:Lateral Movement - impact: 80 - kill_chain_phases: - - Lateral Movement - message: Potential lateral movement and credential stealing via Pass the Token or - Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the logging device $origin_device_id$ - mitre_attack_id: - - T1550 - - T1550.002 - nist: - - PR.PT - - PR.AT - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: origin_device_id - role: - - Other - type: Hostname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - signature_id - - dest_user - - dest_user_id - - origin_device_id - - authentication_method - risk_score: 64 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml deleted file mode 100644 index a7053b9879..0000000000 --- a/dist/ssa/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-04' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules that facilitate access probing with admin - credentials as well as probing access to system services.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: d405af5d-99f1-45af-8dfb-b8f98b764247 -known_false_positives: None identified. -name: Probing Access with Stolen Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is probing access with stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true - OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Privilege Escalation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is probing access with stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_user_id - - dest_device_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -test: - name: Probing Access with Stolen Credentials via PowerSploit modules - SSA Unit - test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test access probing with stolen credentials detections - file: endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml - name: Probing Access with Stolen Credentials via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___rare_parent-child_process_relationship.yml b/dist/ssa/detections/ssa___rare_parent-child_process_relationship.yml deleted file mode 100644 index 4f0ce19970..0000000000 --- a/dist/ssa/detections/ssa___rare_parent-child_process_relationship.yml +++ /dev/null @@ -1,88 +0,0 @@ -author: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: An attacker may use LOLBAS tools spawned from vulnerable applications - not typically used by system administrators. This analytic leverages the Splunk - Streaming ML DSP plugin to find rare parent/child relationships. The list of application - has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -how_to_implement: Collect endpoint data such as sysmon or 4688 events. -id: cf090c78-bcc6-11eb-8529-0242ac130003 -known_false_positives: Some custom tools used by administrators could be used rarely - to launch remotely applications. This might trigger false positives at the beginning - when it has not collected yet enough data to construct the baseline. -name: Rare Parent-Child Process Relationship -product: -- Splunk Behavioral Analytics -references: -- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval parent_process=lower(ucast(map_get(input_event, - "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, - "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where parent_process_name!=null | select parent_process_name, process_name, cmd_line, - timestamp, dest_device_id, dest_user_id | conditional_anomaly conditional="parent_process_name" - target="process_name" | where (process_name="powershell.exe" OR process_name="regsvcs.exe" - OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" - OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" - OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" - OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" - OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" - OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" - OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" - OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" - OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" - OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" - OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" - OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" - OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" - OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" - OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" - OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" - OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" - OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" - OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" - OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" - OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR - process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" - OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" - OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" - OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") - | eval input = (-1)*log(output) | adaptive_threshold algorithm="gaussian" threshold=0.001 - window=604800000L | where label AND input > mean | eval start_time = timestamp, - end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = - create_map(["process_name", process_name, "parent_process_name", parent_process_name, - "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", - cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1203 - - T1059 - - T1053 - - T1072 - nist: - - PR.PT - - DE.CM - product: - - Splunk Behavioral Analytics - required_fields: - - process - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - cmd_line - risk_severity: low - security_domain: endpoint -type: Anomaly -version: 2 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml deleted file mode 100644 index af78d4cb23..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of accounts and groups and access - to them.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 -known_false_positives: None identified. -name: Reconnaissance and Access to Accounts and Groups via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and using specific accounts and groups. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and using specific accounts and groups. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1078 - - T1087 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml deleted file mode 100644 index 48aac644b9..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml +++ /dev/null @@ -1,109 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover accounts, groups and policies - that can be accessed or taken over.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 63422f8e-766c-468f-8133-2ba6795e263b -known_false_positives: None identified. -name: Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and using specific accounts, groups - and policies, such as the last logged on account, a local Net group, etc. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true - OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, - /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true - OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, - /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true - OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, - /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true - OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true - OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, - /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true - OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, - /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true - OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true - OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, - /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true - OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true - OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true - OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, - /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true - OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, - /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, - /(?i)Get-LastLoggedOn/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and using specific accounts, groups - and policies, such as the last logged on account, a local Net group, etc. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1087 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml deleted file mode 100644 index 9cd26d09f7..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml +++ /dev/null @@ -1,98 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules for reconnaissance and access to elements - of Active Directory infrastructure, such as domain identifiers, AD sites and forests, - and trust relations.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: db08ac40-ee14-43e9-9a75-dddd059ef812 -known_false_positives: None identified. -name: Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is seaching for or accessing Active Directory objects - such as domain sites, domain trusts, AD forests, etc. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR - match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true - OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true - OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, - /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true - OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true - OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true - OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, - /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true - OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is seaching for or accessing Active Directory objects - such as domain sites, domain trusts, AD forests, etc. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1199 - - T1482 - - T1590 - - T1591 - - T1595 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml deleted file mode 100644 index 9f677b78bb..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover computers, servers and domains - that can be accessed or taken over.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: fe1c4c5a-09f3-4b43-8129-560a7f38a08b -known_false_positives: None identified. -name: Reconnaissance and Access to Computers and Domains via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is seaching for or accessing domain controllers, - computers, file servers, etc. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR - match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true - OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true - OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, - /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is seaching for or accessing domain controllers, computers, - file servers, etc. Operation is performed at the device $dest_device_id$, by the - account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1592 - - T1590 - - T1087 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml deleted file mode 100644 index 4efdb3ecff..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml +++ /dev/null @@ -1,81 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of computers and servers and access - to them.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 -known_false_positives: None identified. -name: Reconnaissance and Access to Computers via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is collecting information about computers. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::ServerInfo/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is collecting information about computers. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ - mitre_attack_id: - - T1592 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml deleted file mode 100644 index 1637bfac4c..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml +++ /dev/null @@ -1,98 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover and access operating system - elements, such as processes, services, registry locations, security packages and - files.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c1d33ad9-1727-4f9f-a474-4adbe4fed68a -known_false_positives: None identified. -name: Reconnaissance and Access to Operating System Elements via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and tapping into ongoing processes, - mounted drives or other operating system elements. Operation is performed at the - device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true - OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, - /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR - match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true - OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, - /(?i)Get-RegistryMountedDrive/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and tapping into ongoing processes, - mounted drives or other operating system elements. Operation is performed at the - device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1057 - - T1083 - - T1592.002 - - T1046 - - T1012 - - T1007 - - T1047 - - T1592 - - T1518 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml deleted file mode 100644 index cc69c9c467..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml +++ /dev/null @@ -1,80 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery and access to services and processes.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 0243d37c-57c1-4182-bfd1-39b212255fc8 -known_false_positives: None identified. -name: Reconnaissance and Access to Processes and Services via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is listing processes and services. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is listing processes and services. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1007 - - T1046 - - T1057 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml deleted file mode 100644 index 4ea264cc5b..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery and access to network shares.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f -known_false_positives: None identified. -name: Reconnaissance and Access to Shared Resources via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::share/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Lateral Movement - - Stage:Collection - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml deleted file mode 100644 index dd4633a38e..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover and access network and distributed - file system shares.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 6b7ca431-6b1e-4b40-9589-21cb368e369e -known_false_positives: None identified. -name: Reconnaissance and Access to Shared Resources via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true - OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, - /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true - OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, - /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Lateral Movement - - Stage:Collection - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml deleted file mode 100644 index c79a306b71..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml +++ /dev/null @@ -1,101 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules that discover opportunities for malicious - access and persistence. Some examples include access to admin accounts, weak access - control policies, landing paths for dropping malicious software or data to exfiltrate, - registry locations to land autorun parameters, task scheduling opportunities, as - well as services and system files that can be compromised.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 -known_false_positives: None identified. -name: Reconnaissance of Access and Persistence Opportunities via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for an entry point into the infrastructure, - such as local admin accounts, opportunities to hijack processes, unattended install - files, or modifiable access objects. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true - OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, - /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true - OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, - /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true - OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, - /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true - OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, - /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true - OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, - /(?i)Get-UnquotedService/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for an entry point into the infrastructure, - such as local admin accounts, opportunities to hijack processes, unattended install - files, or modifiable access objects. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1053 - - T1068 - - T1078 - - T1543 - - T1547 - - T1574 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml deleted file mode 100644 index 4011dcfffe..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules for reconnaissance of connectivity.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 -known_false_positives: None identified. -name: Reconnaissance of Connectivity via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is performing port scans or searching for various - connectivity details such as DNS data, proxies, or ongoing RDP connections. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true - OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, - /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, - /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true - OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is performing port scans or searching for various connectivity - details such as DNS data, proxies, or ongoing RDP connections. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml deleted file mode 100644 index cbfc35bd95..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies reconnaissance of credential stores and use of CryptoAPI services by - Mimikatz modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 5facee5b-79e4-47ab-b0e6-c625acc0554f -known_false_positives: None identified. -name: Reconnaissance of Credential Stores and Services via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and accessing credential stores. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, - /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true - OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and accessing credential stores. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1098 - - T1590.001 - - T1078 - - T1589.001 - - T1590 - - T1068 - - T1589 - - T1590.003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml deleted file mode 100644 index c100454874..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml +++ /dev/null @@ -1,83 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules for assessment of presence of defensive tools.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 24b4e659-63a2-4e7b-89ac-87dd659c7110 -known_false_positives: None identified. -name: Reconnaissance of Defensive Tools via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is looking for presence of anti virus software. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-AVSignature/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 40 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is looking for presence of anti virus software. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1592.002 - - T1595.002 - - T1592 - - T1595 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 40 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml b/dist/ssa/detections/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml deleted file mode 100644 index a919f28981..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml +++ /dev/null @@ -1,82 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules for assessment of privilege escalation opportunities.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: b9b4492c-2af8-449b-beb4-b1b78d963321 -known_false_positives: None identified. -name: Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is engaging its privilege escalation module. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Invoke-PrivescAudit/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is engaging its privilege escalation module. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml deleted file mode 100644 index 0232e39486..0000000000 --- a/dist/ssa/detections/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of process or service hijacking - opportunities via Microsoft Detours compatibility. Microsoft Detours is an open - source library for intercepting, monitoring and instrumenting binary functions on - Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory - code for target functions. The Detours package also contains utilities to attach - arbitrary DLLs and data segments called payloads to any Win32 binary.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: fc5c1cbd-7494-4314-aad2-458d6fd4fada -known_false_positives: None identified. -name: Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -- https://en.wikipedia.org/wiki/Microsoft_Detours -risk_message: Mimikatz malware is looking for and invoking Microsoft Detours package - that enables spoofing of in-memory code. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)misc::detours/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is looking for and invoking Microsoft Detours package - that enables spoofing of in-memory code. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1543 - - T1055 - - T1574 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___resize_shadowstorage_volume.yml b/dist/ssa/detections/ssa___resize_shadowstorage_volume.yml deleted file mode 100644 index aeb81926a4..0000000000 --- a/dist/ssa/detections/ssa___resize_shadowstorage_volume.yml +++ /dev/null @@ -1,105 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: The following analytic identifies the resizing of shadowstorage using - vssadmin.exe to avoid the shadow volumes being made again. This technique is typically - found used by adversaries during a ransomware event and a precursor to deleting - the shadowstorage. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: dbc30554-d27e-11eb-9e5e-acde48001122 -known_false_positives: System administrators may resize the shadowstorage for valid - purposes. Filter as needed. -name: Resize Shadowstorage Volume -product: -- Splunk Behavioral Analytics -references: -- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html -- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow - copy to perform offline password cracking. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%resize%") AND like(cmd_line, "%shadowstorage%") - AND like(cmd_line, "%maxsize%") AND process_name="vssadmin.exe" | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - Clop Ransomware - - Ransomware - cis20: - - CIS 10 - - CIS 13 - confidence: 80 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log - impact: 80 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow - copy to perform offline password cracking. - mitre_attack_id: - - T1489 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 64 - risk_severity: low - security_domain: endpoint -test: - name: Resize Shadowstorage Volume Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test for resizing the shadow storage of a machine - file: endpoint/ssa___resize_shadowstorage_volume.yml - name: Resize Shadowstorage Volume - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/detections/ssa___sdelete_application_execution.yml b/dist/ssa/detections/ssa___sdelete_application_execution.yml deleted file mode 100644 index 53541e83fe..0000000000 --- a/dist/ssa/detections/ssa___sdelete_application_execution.yml +++ /dev/null @@ -1,110 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-15' -description: This analytic will detect the execution of sdelete.exe attempting to - delete potentially important files that may related to adversary or insider threats - to destroy evidence or information sabotage. Sdelete is a SysInternals utility meant - to securely delete files on disk. This tool is commonly used to clear tracks and - artifact on the targeted host. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: fcc52b9a-4616-11ec-8454-acde48001122 -known_false_positives: False positives should be limited, filter as needed. -name: Sdelete Application Execution -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md -risk_message: Sdelete process $process_name$ executed on $dest_device_id$ attempting - to permanently delete files by $dest_user_id$. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), - "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", - null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), - parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), parent_cmd_line=ucast(map_get(input_event, "parent_process"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line - IS NOT NULL AND process_name IS NOT NULL AND like(process_name, "%sdelete%") AND - (like (cmd_line, "%-c %") OR like (cmd_line, "%-f %")OR like (cmd_line, "%-p %") - OR like (cmd_line, "%-r %") OR like (cmd_line, "%-q %") OR like (cmd_line, "%-s - %") OR like (cmd_line, "%-z %") OR like (cmd_line, "%/accepteula%") OR like (cmd_line, - "%-nobanner%")OR like (cmd_line, "%.doc%")OR like (cmd_line, "%.xls%") OR like (cmd_line, - "%.ppt%")OR like (cmd_line, "%.rtf%") OR like (cmd_line, "%.pdf%") OR like (cmd_line, - "%.key%")OR like (cmd_line, "%.log%") OR like (cmd_line, "%.txt%") OR like (cmd_line, - "%.jpg%") OR like (cmd_line, "%.png%") OR like (cmd_line, "%.gif%") OR like (cmd_line, - "%.bmp%") OR like (cmd_line, "%.7z%") OR like (cmd_line, "%.zip%") OR like (cmd_line, - "%.rar%") OR like (cmd_line, "%.tar%") OR like (cmd_line, "%.gz%") OR like (cmd_line, - "%.xls%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "process_path", process_path, "parent_process_name", parent_process_name, - "parent_cmd_line", parent_cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Information Sabotage - confidence: 70 - context: - - Source:Endpoint - - Stage:Execution - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log - impact: 60 - kill_chain_phases: - - Exploitation - message: Sdelete process $process_name$ executed on $dest_device_id$ attempting - to permanently delete files by $dest_user_id$. - mitre_attack_id: - - T1485 - - T1070.004 - - T1070 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest - - user - - parent_process_name - - parent_process - - process_name - - process - - process_id - - process_path - - cmd_line - risk_score: 42 - risk_severity: medium - security_domain: endpoint -test: - name: Sdelete Application Execution Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log - file_name: security.log - source: WinEventLog:Security - description: Test for sdelete execution command - file: endpoint/ssa___sdelete_application_execution.yml - name: Sdelete Application Execution - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/detections/ssa___setting_credentials_via_dsinternals_modules.yml b/dist/ssa/detections/ssa___setting_credentials_via_dsinternals_modules.yml deleted file mode 100644 index f91f7f5062..0000000000 --- a/dist/ssa/detections/ssa___setting_credentials_via_dsinternals_modules.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via DSInternals modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c -known_false_positives: None identified. -name: Setting Credentials via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is accessing, using or setting Active Directory - or Azure credentials and accounts. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true - OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true - OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, - /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true - OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Source:Cloud Data - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is accessing, using or setting Active Directory or - Azure credentials and accounts. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via DSInternals modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - file_name: logAllDSInternalsModules.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_dsinternals_modules.yml - name: Setting Credentials via DSInternals modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___setting_credentials_via_mimikatz_modules.yml b/dist/ssa/detections/ssa___setting_credentials_via_mimikatz_modules.yml deleted file mode 100644 index f2771dd531..0000000000 --- a/dist/ssa/detections/ssa___setting_credentials_via_mimikatz_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via Mimikatz modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c8b84699-7652-4363-910f-efd1ca82f780 -known_false_positives: None identified. -name: Setting Credentials via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is accessing, using or setting account credentials. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is accessing, using or setting account credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_mimikatz_modules.yml - name: Setting Credentials via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___setting_credentials_via_powersploit_modules.yml b/dist/ssa/detections/ssa___setting_credentials_via_powersploit_modules.yml deleted file mode 100644 index 2cfe008d54..0000000000 --- a/dist/ssa/detections/ssa___setting_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via PowerSploit modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 07b2a501-f967-4ddc-9f56-2dce46dfce44 -known_false_positives: None identified. -name: Setting Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is setting passwords on Active Directory accounts. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Set-DomainUserPassword/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is setting passwords on Active Directory accounts. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml - name: Setting Credentials via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___system_process_running_from_unexpected_location.yml b/dist/ssa/detections/ssa___system_process_running_from_unexpected_location.yml deleted file mode 100644 index dd623108e9..0000000000 --- a/dist/ssa/detections/ssa___system_process_running_from_unexpected_location.yml +++ /dev/null @@ -1,280 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-08-25' -description: An attacker tries might try to use different version of a system command - without overriding original, or they might try to avoid some detection running the - process from a different folder. This detection checks that a list of system processes - run inside C:\\Windows\System32 or C:\\Windows\SysWOW64 The list of system processes - has been extracted from https://github.com/splunk/security_content/blob/develop/lookups/is_windows_system_file.csv - and the original detection https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml -how_to_implement: Collect endpoint data such as sysmon or 4688 events. -id: 28179107-099a-464a-94d3-08301e6c055f -known_false_positives: None -name: System Process Running from Unexpected Location -product: -- Splunk Behavioral Analytics -references: [] -risk_message: A system process $process_name$ with commandline $cmd_line$ spawn in - non-default folder path in host $dest_device_id$ -search: ' $ssa_input = | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, - "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), - "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", - null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", - null)), event_id=ucast(map_get(input_event, "event_id"), "string", null); - - $cond_1 = | from $ssa_input | where process_name="arp.exe" OR process_name="adaptertroubleshooter.exe" - OR process_name="applicationframehost.exe" OR process_name="atbroker.exe" OR process_name="authhost.exe" - OR process_name="autoworkplace.exe" OR process_name="axinstui.exe" OR process_name="backgroundtransferhost.exe" - OR process_name="bdehdcfg.exe" OR process_name="bdeuisrv.exe" OR process_name="bdeunlockwizard.exe" - OR process_name="bitlockerdeviceencryption.exe" OR process_name="bitlockerwizard.exe" - OR process_name="bitlockerwizardelev.exe" OR process_name="bytecodegenerator.exe" - OR process_name="camerasettingsuihost.exe" OR process_name="castsrv.exe" OR process_name="certenrollctrl.exe" - OR process_name="checknetisolation.exe" OR process_name="clipup.exe" OR process_name="cloudexperiencehostbroker.exe" - OR process_name="cloudnotifications.exe" OR process_name="cloudstoragewizard.exe" - OR process_name="compmgmtlauncher.exe" OR process_name="compattelrunner.exe" OR - process_name="computerdefaults.exe" OR process_name="credentialuibroker.exe" OR - process_name="dfdwiz.exe" OR process_name="dwwin.exe" OR process_name="dataexchangehost.exe" - OR process_name="defrag.exe" OR process_name="devicedisplayobjectprovider.exe" OR - process_name="deviceeject.exe" OR process_name="deviceenroller.exe" OR process_name="devicepairingwizard.exe" - OR process_name="deviceproperties.exe" OR process_name="disksnapshot.exe" OR process_name="dism.exe" - OR process_name="displayswitch.exe" OR process_name="dmnotificationbroker.exe" OR - process_name="dmomacpmo.exe" OR process_name="dpiscaling.exe" OR process_name="dsmusertask.exe" - OR process_name="dxpserver.exe" OR process_name="edpcleanup.exe" OR process_name="eosnotify.exe" - OR process_name="eap3host.exe" OR process_name="easpoliciesbrokerhost.exe" OR process_name="easeofaccessdialog.exe" - OR process_name="ehstorauthn.exe" OR process_name="fxscover.exe" OR process_name="fxssvc.exe" - OR process_name="fxsunatd.exe" OR process_name="filehistory.exe" OR process_name="fondue.exe" - OR process_name="gamepanel.exe" OR process_name="genvalobj.exe" OR process_name="gettingstarted.exe" - OR process_name="hostname.exe" OR process_name="icsentitlementhost.exe" OR process_name="infdefaultinstall.exe" - OR process_name="installagent.exe" OR process_name="languagecomponentsinstallercomhandler.exe" - OR process_name="launchtm.exe" OR process_name="launchwinapp.exe" OR process_name="legacynetuxhost.exe" - OR process_name="licensemanagershellext.exe" OR process_name="licensingui.exe" OR - process_name="locationnotificationwindows.exe" OR process_name="locationnotifications.exe" - OR process_name="locator.exe" OR process_name="lockapphost.exe" OR process_name="lockscreencontentserver.exe" - OR process_name="logonui.exe" OR process_name="lsaiso.exe" OR process_name="mdeserver.exe" - OR process_name="mdmagent.exe" OR process_name="mdmappinstaller.exe" OR process_name="mrinfo.exe" - OR process_name="mrt.exe" OR process_name="mschedexe.exe" OR process_name="magnify.exe" - OR process_name="mbaeparsertask.exe" OR process_name="mdres.exe" OR process_name="mdsched.exe" - OR process_name="migautoplay.exe" OR process_name="mpsigstub.exe" OR process_name="msspellcheckinghost.exe" - OR process_name="muiunattend.exe" OR process_name="multidigimon.exe" OR process_name="musnotification.exe" - OR process_name="musnotificationux.exe" OR process_name="napstat.exe" OR process_name="netstat.exe" - OR process_name="narrator.exe" OR process_name="netcfgnotifyobjecthost.exe" OR process_name="netevtfwdr.exe" - OR process_name="netproj.exe" OR process_name="netplwiz.exe" OR process_name="networkuxbroker.exe"; - - $cond_2 = | from $ssa_input | where process_name="openwith.exe" OR process_name="optionalfeatures.exe" - OR process_name="pathping.exe" OR process_name="ping.exe" OR process_name="passwordonwakesettingflyout.exe" - OR process_name="pickerhost.exe" OR process_name="pkgmgr.exe" OR process_name="pnpunattend.exe" - OR process_name="pnputil.exe" OR process_name="presentationhost.exe" OR process_name="presentationsettings.exe" - OR process_name="printbrmui.exe" OR process_name="printdialoghost.exe" OR process_name="printdialoghost3d.exe" - OR process_name="printisolationhost.exe" OR process_name="proximityuxhost.exe" OR - process_name="rdspnf.exe" OR process_name="rmactivate.exe" OR process_name="rmactivate_isv.exe" - OR process_name="rmactivate_ssp.exe" OR process_name="rmactivate_ssp_isv.exe" OR - process_name="route.exe" OR process_name="rdpsa.exe" OR process_name="rdpsaproxy.exe" - OR process_name="rdpsauachelper.exe" OR process_name="reagentc.exe" OR process_name="recoverydrive.exe" - OR process_name="register-cimprovider.exe" OR process_name="registeriepkeys.exe" - OR process_name="relpost.exe" OR process_name="remoteposworker.exe" OR process_name="rmclient.exe" - OR process_name="robocopy.exe" OR process_name="rpcping.exe" OR process_name="runlegacycplelevated.exe" - OR process_name="runtimebroker.exe" OR process_name="sihclient.exe" OR process_name="searchfilterhost.exe" - OR process_name="searchindexer.exe" OR process_name="searchprotocolhost.exe" OR - process_name="secedit.exe" OR process_name="sensordataservice.exe" OR process_name="setieinstalleddate.exe" - OR process_name="settingsynchost.exe" OR process_name="slidetoshutdown.exe" OR process_name="smartscreensettings.exe" - OR process_name="sndvol.exe" OR process_name="snippingtool.exe" OR process_name="soundrecorder.exe" - OR process_name="spaceagent.exe" OR process_name="sppextcomobj.exe" OR process_name="srtasks.exe" - OR process_name="stikynot.exe" OR process_name="synchost.exe" OR process_name="sysreseterr.exe" - OR process_name="systempropertiesadvanced.exe" OR process_name="systempropertiescomputername.exe" - OR process_name="systempropertiesdataexecutionprevention.exe" OR process_name="systempropertieshardware.exe" - OR process_name="systempropertiesperformance.exe" OR process_name="systempropertiesprotection.exe" - OR process_name="systempropertiesremote.exe" OR process_name="systemsettingsadminflows.exe" - OR process_name="systemsettingsbroker.exe" OR process_name="systemsettingsremovedevice.exe" - OR process_name="tcpsvcs.exe" OR process_name="tracert.exe" OR process_name="tstheme.exe" - OR process_name="tswbprxy.exe" OR process_name="tapiunattend.exe" OR process_name="taskmgr.exe" - OR process_name="thumbnailextractionhost.exe" OR process_name="tokenbrokercookies.exe" - OR process_name="tpminit.exe" OR process_name="tswpfwrp.exe" OR process_name="ui0detect.exe" - OR process_name="upgraderesultsui.exe" OR process_name="useraccountbroker.exe" OR - process_name="useraccountcontrolsettings.exe" OR process_name="usoclient.exe" OR - process_name="utilman.exe" OR process_name="vssvc.exe" OR process_name="vaultcmd.exe" - OR process_name="vaultsysui.exe" OR process_name="wfs.exe" OR process_name="wmpdmc.exe" - OR process_name="wpdshextautoplay.exe" OR process_name="wscollect.exe" OR process_name="wsmanhttpconfig.exe" - OR process_name="wsreset.exe" OR process_name="wudfhost.exe" OR process_name="wwahost.exe" - OR process_name="wallpaperhost.exe" OR process_name="webcache.exe" OR process_name="werfault.exe" - OR process_name="werfaultsecure.exe" OR process_name="winsat.exe" OR process_name="windows.media.backgroundplayback.exe" - OR process_name="windowsactiondialog.exe" OR process_name="windowsanytimeupgrade.exe" - OR process_name="windowsanytimeupgraderesults.exe"; - - $cond_3 = | from $ssa_input | where process_name="windowsanytimeupgradeui.exe" OR - process_name="windowsupdateelevatedinstaller.exe" OR process_name="workfolders.exe" - OR process_name="wpcmon.exe" OR process_name="acu.exe" OR process_name="aitagent.exe" - OR process_name="aitstatic.exe" OR process_name="alg.exe" OR process_name="appidcertstorecheck.exe" - OR process_name="appidpolicyconverter.exe" OR process_name="at.exe" OR process_name="attrib.exe" - OR process_name="audiodg.exe" OR process_name="auditpol.exe" OR process_name="autochk.exe" - OR process_name="autoconv.exe" OR process_name="autofmt.exe" OR process_name="baaupdate.exe" - OR process_name="backgroundtaskhost.exe" OR process_name="bcastdvr.exe" OR process_name="bcdboot.exe" - OR process_name="bcdedit.exe" OR process_name="bdechangepin.exe" OR process_name="bdeunlock.exe" - OR process_name="bitsadmin.exe" OR process_name="bootcfg.exe" OR process_name="bootim.exe" - OR process_name="bootsect.exe" OR process_name="bridgeunattend.exe" OR process_name="browser_broker.exe" - OR process_name="bthudtask.exe" OR process_name="cacls.exe" OR process_name="calc.exe" - OR process_name="cdpreference.exe" OR process_name="certreq.exe" OR process_name="certutil.exe" - OR process_name="change.exe" OR process_name="changepk.exe" OR process_name="charmap.exe" - OR process_name="chglogon.exe" OR process_name="chgport.exe" OR process_name="chgusr.exe" - OR process_name="chkdsk.exe" OR process_name="chkntfs.exe" OR process_name="choice.exe" - OR process_name="cipher.exe" OR process_name="cleanmgr.exe" OR process_name="cliconfg.exe" - OR process_name="clip.exe" OR process_name="cmd.exe" OR process_name="cmdkey.exe" - OR process_name="cmdl32.exe" OR process_name="cmmon32.exe" OR process_name="cmstp.exe" - OR process_name="cofire.exe" OR process_name="colorcpl.exe" OR process_name="comp.exe" - OR process_name="compact.exe" OR process_name="conhost.exe" OR process_name="consent.exe" - OR process_name="control.exe" OR process_name="convert.exe" OR process_name="credwiz.exe" - OR process_name="cscript.exe" OR process_name="csrss.exe" OR process_name="ctfmon.exe" - OR process_name="cttune.exe" OR process_name="cttunesvr.exe" OR process_name="dashost.exe" - OR process_name="dccw.exe" OR process_name="dcomcnfg.exe" OR process_name="ddodiag.exe" - OR process_name="dfrgui.exe" OR process_name="dialer.exe" OR process_name="diantz.exe" - OR process_name="dinotify.exe" OR process_name="diskpart.exe" OR process_name="diskperf.exe" - OR process_name="diskraid.exe" OR process_name="dispdiag.exe" OR process_name="djoin.exe" - OR process_name="dllhost.exe" OR process_name="dllhst3g.exe" OR process_name="dmcertinst.exe" - OR process_name="dmcfghost.exe" OR process_name="dmclient.exe" OR process_name="dnscacheugc.exe" - OR process_name="doskey.exe" OR process_name="dpapimig.exe" OR process_name="dpnsvr.exe" - OR process_name="driverquery.exe" OR process_name="drvcfg.exe" OR process_name="drvinst.exe" - OR process_name="dsregcmd.exe" OR process_name="dstokenclean.exe" OR process_name="dvdplay.exe" - OR process_name="dvdupgrd.exe" OR process_name="dwm.exe" OR process_name="dxdiag.exe" - OR process_name="easinvoker.exe" OR process_name="efsui.exe"; - - $cond_4 = | from $ssa_input | where process_name="embeddedapplauncher.exe" OR process_name="esentutl.exe" - OR process_name="eudcedit.exe" OR process_name="eventcreate.exe" OR process_name="eventvwr.exe" - OR process_name="expand.exe" OR process_name="extrac32.exe" OR process_name="fc.exe" - OR process_name="fhmanagew.exe" OR process_name="find.exe" OR process_name="findstr.exe" - OR process_name="finger.exe" OR process_name="fixmapi.exe" OR process_name="fltmc.exe" - OR process_name="fodhelper.exe" OR process_name="fontdrvhost.exe" OR process_name="fontview.exe" - OR process_name="forfiles.exe" OR process_name="fsavailux.exe" OR process_name="fsquirt.exe" - OR process_name="fsutil.exe" OR process_name="ftp.exe" OR process_name="fvenotify.exe" - OR process_name="fveprompt.exe" OR process_name="getmac.exe" OR process_name="gpresult.exe" - OR process_name="gpscript.exe" OR process_name="gpupdate.exe" OR process_name="grpconv.exe" - OR process_name="hdwwiz.exe" OR process_name="help.exe" OR process_name="hwrcomp.exe" - OR process_name="hwrreg.exe" OR process_name="icacls.exe" OR process_name="icardagt.exe" - OR process_name="icsunattend.exe" OR process_name="ie4uinit.exe" OR process_name="ieunatt.exe" - OR process_name="ieetwcollector.exe" OR process_name="iexpress.exe" OR process_name="immersivetpmvscmgrsvr.exe" - OR process_name="ipconfig.exe" OR process_name="irftp.exe" OR process_name="iscsicli.exe" - OR process_name="iscsicpl.exe" OR process_name="isoburn.exe" OR process_name="klist.exe" - OR process_name="ksetup.exe" OR process_name="ktmutil.exe" OR process_name="label.exe" - OR process_name="licensingdiag.exe" OR process_name="lodctr.exe" OR process_name="logagent.exe" - OR process_name="logman.exe" OR process_name="logoff.exe" OR process_name="lpkinstall.exe" - OR process_name="lpksetup.exe" OR process_name="lpremove.exe" OR process_name="lsass.exe" - OR process_name="lsm.exe" OR process_name="makecab.exe" OR process_name="manage-bde.exe" - OR process_name="mblctr.exe" OR process_name="mcbuilder.exe" OR process_name="mctadmin.exe" - OR process_name="mfpmp.exe" OR process_name="mmc.exe" OR process_name="mobsync.exe" - OR process_name="mountvol.exe" OR process_name="mpnotify.exe" OR process_name="msconfig.exe" - OR process_name="msdt.exe" OR process_name="msdtc.exe" OR process_name="msfeedssync.exe" - OR process_name="msg.exe" OR process_name="mshta.exe" OR process_name="msiexec.exe" - OR process_name="msinfo32.exe" OR process_name="mspaint.exe" OR process_name="msra.exe" - OR process_name="mstsc.exe" OR process_name="mtstocom.exe" OR process_name="nbtstat.exe" - OR process_name="ndadmin.exe" OR process_name="net.exe" OR process_name="net1.exe" - OR process_name="netbtugc.exe" OR process_name="netcfg.exe" OR process_name="netiougc.exe" - OR process_name="netsh.exe" OR process_name="newdev.exe" OR process_name="nltest.exe" - OR process_name="notepad.exe" OR process_name="nslookup.exe" OR process_name="ntoskrnl.exe" - OR process_name="ntprint.exe" OR process_name="ocsetup.exe" OR process_name="odbcad32.exe" - OR process_name="odbcconf.exe" OR process_name="omadmclient.exe" OR process_name="omadmprc.exe"; - - $cond_5 = | from $ssa_input | where process_name="openfiles.exe" OR process_name="osk.exe" - OR process_name="p2phost.exe" OR process_name="pcalua.exe" OR process_name="pcaui.exe" - OR process_name="pcawrk.exe" OR process_name="pcwrun.exe" OR process_name="perfmon.exe" - OR process_name="phoneactivate.exe" OR process_name="plasrv.exe" OR process_name="poqexec.exe" - OR process_name="powercfg.exe" OR process_name="prevhost.exe" OR process_name="print.exe" - OR process_name="printfilterpipelinesvc.exe" OR process_name="printui.exe" OR process_name="proquota.exe" - OR process_name="provtool.exe" OR process_name="psr.exe" OR process_name="pwlauncher.exe" - OR process_name="qappsrv.exe" OR process_name="qprocess.exe" OR process_name="query.exe" - OR process_name="quser.exe" OR process_name="qwinsta.exe" OR process_name="rasautou.exe" - OR process_name="rasdial.exe" OR process_name="raserver.exe" OR process_name="rasphone.exe" - OR process_name="rdpclip.exe" OR process_name="rdpinput.exe" OR process_name="rdrleakdiag.exe" - OR process_name="recdisc.exe" OR process_name="recover.exe" OR process_name="reg.exe" - OR process_name="regedt32.exe" OR process_name="regini.exe" OR process_name="regsvr32.exe" - OR process_name="rekeywiz.exe" OR process_name="relog.exe" OR process_name="repair-bde.exe" - OR process_name="replace.exe" OR process_name="reset.exe" OR process_name="resmon.exe" - OR process_name="rmttpmvscmgrsvr.exe" OR process_name="rrinstaller.exe" OR process_name="rstrui.exe" - OR process_name="runas.exe" OR process_name="rundll32.exe" OR process_name="runonce.exe" - OR process_name="rwinsta.exe" OR process_name="sbunattend.exe" OR process_name="sc.exe" - OR process_name="schtasks.exe" OR process_name="sdbinst.exe" OR process_name="sdchange.exe" - OR process_name="sdclt.exe" OR process_name="sdiagnhost.exe" OR process_name="secinit.exe" - OR process_name="services.exe" OR process_name="sessionmsg.exe" OR process_name="sethc.exe" - OR process_name="setspn.exe" OR process_name="setupcl.exe" OR process_name="setupugc.exe" - OR process_name="setx.exe" OR process_name="sfc.exe" OR process_name="shadow.exe" - OR process_name="shrpubw.exe" OR process_name="shutdown.exe" OR process_name="sigverif.exe" - OR process_name="sihost.exe" OR process_name="slui.exe" OR process_name="smss.exe" - OR process_name="snmptrap.exe" OR process_name="sort.exe" OR process_name="spinstall.exe" - OR process_name="spoolsv.exe" OR process_name="sppsvc.exe" OR process_name="spreview.exe" - OR process_name="srdelayed.exe" OR process_name="subst.exe" OR process_name="svchost.exe" - OR process_name="sxstrace.exe" OR process_name="syskey.exe" OR process_name="systeminfo.exe" - OR process_name="systemreset.exe" OR process_name="systray.exe" OR process_name="tabcal.exe" - OR process_name="takeown.exe" OR process_name="taskeng.exe" OR process_name="taskhost.exe" - OR process_name="taskhostw.exe" OR process_name="taskkill.exe" OR process_name="tasklist.exe" - OR process_name="taskmgr.exe" OR process_name="tcmsetup.exe" OR process_name="timeout.exe" - OR process_name="tpmvscmgr.exe" OR process_name="tpmvscmgrsvr.exe"; - - $cond_6 = | from $ssa_input | where process_name="tracerpt.exe" OR process_name="tscon.exe" - OR process_name="tsdiscon.exe" OR process_name="tskill.exe" OR process_name="typeperf.exe" - OR process_name="tzsync.exe" OR process_name="tzutil.exe" OR process_name="ucsvc.exe" - OR process_name="unlodctr.exe" OR process_name="unregmp2.exe" OR process_name="upnpcont.exe" - OR process_name="userinit.exe" OR process_name="vds.exe" OR process_name="vdsldr.exe" - OR process_name="verclsid.exe" OR process_name="verifier.exe" OR process_name="verifiergui.exe" - OR process_name="vmicsvc.exe" OR process_name="vssadmin.exe" OR process_name="w32tm.exe" - OR process_name="waitfor.exe" OR process_name="wbadmin.exe" OR process_name="wbengine.exe" - OR process_name="wecutil.exe" OR process_name="wermgr.exe" OR process_name="wevtutil.exe" - OR process_name="wextract.exe" OR process_name="where.exe" OR process_name="whoami.exe" - OR process_name="wiaacmgr.exe" OR process_name="wiawow64.exe" OR process_name="wifitask.exe" - OR process_name="wimserv.exe" OR process_name="wininit.exe" OR process_name="winload.exe" - OR process_name="winlogon.exe" OR process_name="winresume.exe" OR process_name="winrs.exe" - OR process_name="winrshost.exe" OR process_name="winver.exe" OR process_name="wisptis.exe" - OR process_name="wkspbroker.exe" OR process_name="wksprt.exe" OR process_name="wlanext.exe" - OR process_name="wlrmdr.exe" OR process_name="wowreg32.exe" OR process_name="wpnpinst.exe" - OR process_name="wpr.exe" OR process_name="write.exe" OR process_name="wscript.exe" - OR process_name="wsmprovhost.exe" OR process_name="wsqmcons.exe" OR process_name="wuapihost.exe" - OR process_name="wuapp.exe" OR process_name="wuauclt.exe" OR process_name="wusa.exe" - OR process_name="xcopy.exe" OR process_name="xpsrchvw.exe" OR process_name="xwizard.exe"; - - | from $cond_1 | union $cond_2 | union $cond_3 | union $cond_4 | union $cond_5 | - union $cond_6 | where match_regex(process_path, /(?i)\\windows\\system32/)=false - AND match_regex(process_path, /(?i)\\windows\\syswow64/)=false | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(device, user), body=create_map(["event_id", - event_id, "process_path", process_path, "process_name", process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Defense Evasion Tactics - - Masquerading - Rename System Utilities - cis20: - - CIS 8 - confidence: 80 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/system_process_running_unexpected_location/windows-security.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: A system process $process_name$ with commandline $cmd_line$ spawn in non-default - folder path in host $dest_device_id$ - mitre_attack_id: - - T1036 - nist: - - PR.PT - - DE.CM - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - _time - - dest_user_id - - process_path - risk_score: 56 - risk_severity: low - security_domain: endpoint -type: Anomaly -version: 3 diff --git a/dist/ssa/detections/ssa___unusually_long_command_line.yml b/dist/ssa/detections/ssa___unusually_long_command_line.yml deleted file mode 100644 index 7431805fa7..0000000000 --- a/dist/ssa/detections/ssa___unusually_long_command_line.yml +++ /dev/null @@ -1,87 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-06' -description: Command lines that are extremely long may be indicative of malicious - activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin - to help identify command lines with lengths that are unusual for a given user. This - detection is inspired on Unusually Long Command Line authored by Rico Valdez. -how_to_implement: You must be ingesting sysmon endpoint data that monitors command - lines. -id: 58f43aba-1775-445e-b19c-be2b87d83ae3 -known_false_positives: This detection may flag suspiciously long command lines when - there is not sufficient evidence (samples) for a given process that this detection - is tracking; or when there is high variability in the length of the command line - for the tracked process. Also, some legitimate applications may use long command - lines. Such is the case of Ansible, that encodes Powershell scripts using long base64. - Attackers may use this technique to obfuscate their payloads. -name: Unusually Long Command Line -product: -- Splunk Behavioral Analytics -references: [] -risk_message: A process $process_name$ with a long commandline $cmd_line$ executed - in host $dest_device_id$ -search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval cmd_line=ucast(map_get(input_event, "process"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), - process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line!=null and dest_user_id!=null | eval - cmd_line_norm=replace(cast(cmd_line, "string"), /\s(--?\w+)|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, - /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, - ""))) | select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, - input | adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 - | where label AND quantile>0.99 | first_time_event input_columns=["dest_device_id", - "cmd_line"] | where first_time_dest_device_id_cmd_line | eval start_time = timestamp, - end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", - event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - confidence: 40 - context: - - source:endpoint - - stage: Defense Evasion - impact: 30 - kill_chain_phases: - - Actions on Objectives - message: A process $process_name$ with a long commandline $cmd_line$ executed in - host $dest_device_id$ - nist: - - PR.PT - - DE.CM - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 12 - risk_severity: medium - security_domain: endpoint -test: - name: Unusually Long Command Line - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/unusally_cmd_line/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test unusually long command lines - file: endpoint/ssa___unusually_long_command_line.yml - name: Unusually Long Command Line - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/detections/ssa___wbadmin_delete_system_backups.yml b/dist/ssa/detections/ssa___wbadmin_delete_system_backups.yml deleted file mode 100644 index 1d7a52b1dd..0000000000 --- a/dist/ssa/detections/ssa___wbadmin_delete_system_backups.yml +++ /dev/null @@ -1,102 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator - Tool) that delete backup files. This is typically used by ransomware to prevent - recovery. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: 71efbf52-4dbb-4c00-a520-306aa546cbb7 -known_false_positives: Administrators may modify the boot configuration. -name: WBAdmin Delete System Backups -product: -- Splunk Behavioral Analytics -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md -- https://thedfirreport.com/2020/10/08/ryuks-return/ -- https://attack.mitre.org/techniques/T1490/ -- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system - backups. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" - AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, - "%systemstatebackup%") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Ryuk Ransomware - - Ransomware - cis20: - - CIS 8 - confidence: 50 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: [] - impact: 30 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system - backups. - mitre_attack_id: - - T1490 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 15 - risk_severity: medium - security_domain: endpoint -test: - name: WBAdmin Delete System Backups - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - description: Test detection of WBAdmin Delete System Backups - file: endpoint/ssa___wbadmin_delete_system_backups.yml - name: WBAdmin Delete System Backups - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/detections/ssa___wevtutil_usage_to_clear_logs.yml b/dist/ssa/detections/ssa___wevtutil_usage_to_clear_logs.yml deleted file mode 100644 index aaeeca58e6..0000000000 --- a/dist/ssa/detections/ssa___wevtutil_usage_to_clear_logs.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-06-15' -description: The wevtutil.exe application is the windows event log utility. This searches - for wevtutil.exe with parameters for clearing the application, security, setup, - powershell, sysmon, or system event logs. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: 5438113c-cdd9-11eb-93b8-acde48001122 -known_false_positives: The wevtutil.exe application is a legitimate Windows event - log utility. Administrators may use it to manage Windows event logs. -name: WevtUtil Usage To Clear Logs -product: -- Splunk Behavioral Analytics -references: -- https://www.splunk.com/en_us/blog/security/detecting-clop-ransomware.html -risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear - event logs in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, - /(?i)security/)=true OR match_regex(cmd_line, /(?i)system/)=true OR match_regex(cmd_line, - /(?i)sysmon/)=true OR match_regex(cmd_line, /(?i)application/)=true OR match_regex(cmd_line, - /(?i)setup/)=true OR match_regex(cmd_line, /(?i)powershell/)=true) AND process_name="wevtutil.exe" - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, - "process_name", process_name, "parent_process_name", parent_process_name, "process_path", - process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Log Manipulation - - Ransomware - - Clop Ransomware - cis20: - - CIS 8 - - CIS 13 - confidence: 90 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log - impact: 70 - kill_chain_phases: - - Exploitation - message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear - event logs in host $dest_device_id$ - mitre_attack_id: - - T1070 - - T1070.001 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -test: - name: WevtUtil Usage To Clear Logs Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log - file_name: clear_evt.log - source: WinEventLog:Security - description: Test for wevtutil clear logs command - file: endpoint/ssa___wevtutil_usage_to_clear_logs.yml - name: WevtUtil Usage To Clear Logs - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___wevtutil_usage_to_disable_logs.yml b/dist/ssa/detections/ssa___wevtutil_usage_to_disable_logs.yml deleted file mode 100644 index 72fb55c1ca..0000000000 --- a/dist/ssa/detections/ssa___wevtutil_usage_to_disable_logs.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-06-15' -description: This search is to detect execution of wevtutil.exe to disable logs. This - technique was seen in several ransomware to disable the event logs to evade alerts - and detections in compromised host. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: a4bdc944-cdd9-11eb-ac97-acde48001122 -known_false_positives: network operator may disable audit event logs for debugging - purposes. -name: Wevtutil Usage To Disable Logs -product: -- Splunk Behavioral Analytics -references: -- https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/ -risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable - event logs in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, "%/e:false%") - AND process_name="wevtutil.exe" | eval start_time=timestamp, end_time=timestamp, - entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, - "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, - "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, - "process_path", process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Log Manipulation - - Ransomware - cis20: - - CIS 8 - - CIS 13 - confidence: 90 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log - impact: 70 - kill_chain_phases: - - Exploitation - message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable - event logs in host $dest_device_id$ - mitre_attack_id: - - T1070 - - T1070.001 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -test: - name: Wevtutil Usage To Disable Logs Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log - file_name: disable_evt.log - source: WinEventLog:Security - description: Test for wevtutil disable logs command - file: endpoint/ssa___wevtutil_usage_to_disable_logs.yml - name: Wevtutil Usage To Disable Logs - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/detections/ssa___windows_curl_upload_to_remote_destination.yml b/dist/ssa/detections/ssa___windows_curl_upload_to_remote_destination.yml deleted file mode 100644 index 586a4f6173..0000000000 --- a/dist/ssa/detections/ssa___windows_curl_upload_to_remote_destination.yml +++ /dev/null @@ -1,115 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-03' -description: 'The following analytic identifies the use of Windows Curl.exe uploading - a file to a remote destination. \ - - `-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. - \ - - `-d` or `--data` POST is the HTTP method that was invented to send data to a receiving - web application, and it is, for example, how most common HTML forms on the web work. - \ - - HTTP multipart formposts are done with `-F`, but this appears to not be compatible - with the Windows version of Curl. Will update if identified adversary tradecraft. - \ - - Adversaries may use one of the three methods based on the remote destination and - what they are attempting to upload (zip vs txt). During triage, review parallel - processes for further behavior. In addition, identify if the upload was successful - in network logs. If a file was uploaded, isolate the endpoint and review.' -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: cc8d046a-543b-11ec-b864-acde48001122 -known_false_positives: False positives may be limited to source control applications - and may be required to be filtered out. -name: Windows Curl Upload to Remote Destination -product: -- Splunk Behavioral Analytics -references: -- https://everything.curl.dev/usingcurl/uploads -- https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409 -- https://twitter.com/d1r4c/status/1279042657508081664?s=20 -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote - destination. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - - | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="curl.exe" - AND (like (cmd_line, "%-T %") OR like (cmd_line, "%--upload-file %")OR like (cmd_line, - "%-d %") OR like (cmd_line, "%--data %") OR like (cmd_line, "%-F %")) - - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, - "process_name", process_name, "parent_process_name", parent_process_name, "process_path", - process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Ingress Tool Transfer - automated_detection_testing: passed - confidence: 100 - context: - - Source:Endpoint - - Stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log - impact: 80 - kill_chain_phases: - - Exfiltration - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote - destination. - mitre_attack_id: - - T1105 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Windows Curl Upload to Remote Destination Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:security - file: endpoint/ssa___windows_curl_upload_to_remote_destination.yml - name: Windows Curl Upload to Remote Destination - pass_condition: '@count_gt(0)' -type: TTP -version: 1 From 871a66ebaece2e406d475d5b359df55cc3c1977f Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 10 Jan 2022 14:59:29 -0500 Subject: [PATCH 3/9] changed to use srs and complex division --- bin/generate.py | 14 ++- ...ssa___anomalous_usage_of_archive_tools.yml | 96 +++++++++++++++ ...tolen_credentials_via_mimikatz_modules.yml | 85 ++++++++----- ...en_credentials_via_powersploit_modules.yml | 71 +++++++---- ...tial_strength_via_dsinternals_modules.yml} | 50 ++++---- .../ssa___attempt_to_delete_services.yml | 106 ++++++++++++++++ .../ssa___attempt_to_disable_services.yml | 105 ++++++++++++++++ ..._bcdedit_failure_recovery_modification.yml | 99 +++++++++++++++ ...ternals_credential_conversion_modules.yml} | 55 +++++---- ...icative_of_use_of_dsinternals_modules.yml} | 52 ++++---- ...indicative_of_use_of_mimikatz_modules.yml} | 45 ++++--- ...icative_of_use_of_powersploit_modules.yml} | 45 ++++--- dist/ssa/complex/ssa___delete_a_net_user.yml | 109 +++++++++++++++++ ...___deny_permission_using_cacls_utility.yml | 92 ++++++++++++++ ...detect_dump_lsass_memory_using_comsvcs.yml | 87 +++++++++++++ ...ohibited_applications_spawning_cmd_exe.yml | 103 ++++++++++++++++ ...ssa___detect_rclone_command-line_usage.yml | 97 +++++++++++++++ .../ssa___disable_net_user_account.yml | 104 ++++++++++++++++ ...___dns_exfiltration_using_nslookup_app.yml | 104 ++++++++++++++++ .../ssa/complex/ssa___fsutil_zeroing_file.yml | 97 +++++++++++++++ ...__grant_permission_using_cacls_utility.yml | 92 ++++++++++++++ ..._user_content_via_powersploit_modules.yml} | 41 ++++--- ...count_creation_via_powersploit_modules.yml | 49 +++++--- ...deletion_of_logs_via_mimikatz_modules.yml} | 40 +++--- ...g_of_accounts_via_dsinternals_modules.yml} | 38 +++--- ..._and_policies_via_dsinternals_modules.yml} | 41 ++++--- ...tory_elements_via_powersploit_modules.yml} | 41 ++++--- ...nd_persistence_via_powersploit_modules.yml | 53 +++++--- ...ivilege_elevation_via_mimikatz_modules.yml | 49 +++++--- ...d_process_control_via_mimikatz_modules.yml | 50 +++++--- ...rocess_control_via_powersploit_modules.yml | 54 +++++--- ...fy_acls_permission_of_files_or_folders.yml | 96 +++++++++++++++ ...ction_by_machine_learning_method_-_ssa.yml | 0 ...en_credentials_via_powersploit_modules.yml | 53 +++++--- ...ounts_and_groups_via_mimikatz_modules.yml} | 39 +++--- ..._and_policies_via_powersploit_modules.yml} | 40 +++--- ...nfrastructure_via_powersploit_modules.yml} | 43 ++++--- ...s_and_domains_via_powersploit_modules.yml} | 39 +++--- ...ess_to_computers_via_mimikatz_modules.yml} | 41 ++++--- ...stem_elements_via_powersploit_modules.yml} | 41 ++++--- ...ses_and_services_via_mimikatz_modules.yml} | 39 +++--- ...shared_resources_via_mimikatz_modules.yml} | 40 +++--- ...red_resources_via_powersploit_modules.yml} | 41 ++++--- ...opportunities_via_powersploit_modules.yml} | 48 +++++--- ..._connectivity_via_powersploit_modules.yml} | 41 ++++--- ...res_and_services_via_mimikatz_modules.yml} | 39 +++--- ...fensive_tools_via_powersploit_modules.yml} | 40 +++--- ...opportunities_via_powersploit_modules.yml} | 40 +++--- ...ng_opportunities_via_mimikatz_modules.yml} | 51 ++++---- .../ssa___resize_shadowstorage_volume.yml | 105 ++++++++++++++++ .../ssa___sdelete_application_execution.yml | 110 +++++++++++++++++ ...ng_credentials_via_dsinternals_modules.yml | 49 +++++--- ...tting_credentials_via_mimikatz_modules.yml | 49 +++++--- ...ng_credentials_via_powersploit_modules.yml | 49 +++++--- .../ssa___wbadmin_delete_system_backups.yml | 102 ++++++++++++++++ .../ssa___wevtutil_usage_to_clear_logs.yml | 97 +++++++++++++++ .../ssa___wevtutil_usage_to_disable_logs.yml | 93 ++++++++++++++ ...dows_curl_upload_to_remote_destination.yml | 115 ++++++++++++++++++ ...l_extraction_fgdump_cachedump_s_option.yml | 92 -------------- ...l_extraction_fgdump_cachedump_v_option.yml | 85 ------------- ...al_extraction_getaddbaccount_from_dump.yml | 77 ------------ ...ial_extraction_lazagne_command_options.yml | 76 ------------ ...al_extraction_ms_debuggers_kernel_peek.yml | 86 ------------- ...ntial_extraction_ms_debuggers_z_option.yml | 82 ------------- .../ssa/deprecated/ssa___detect_pass_hash.yml | 83 ------------- dist/ssa/srs/ssa___detect_kerberoasting.yml | 94 ++++++++++++++ ...xcessive_number_of_office_files_copied.yml | 64 ++++++++++ ..._first_time_seen_command_line_argument.yml | 89 ++++++++++++++ .../ssa___high_file_deletion_frequency.yml | 85 +++++++++++++ ...lbas_applications_in_short_time_period.yml | 95 +++++++++++++++ ...ction_by_machine_learning_method_-_ssa.yml | 62 ++++++++++ ...ash_observed_at_the_destination_device.yml | 102 ++++++++++++++++ ...observed_by_an_event_collecting_device.yml | 103 ++++++++++++++++ ...rare_parent-child_process_relationship.yml | 88 ++++++++++++++ .../srs/ssa___unusually_long_command_line.yml | 87 +++++++++++++ ...dows_curl_upload_to_remote_destination.yml | 2 +- 76 files changed, 3950 insertions(+), 1206 deletions(-) create mode 100644 dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml rename dist/ssa/{deprecated => complex}/ssa___applying_stolen_credentials_via_mimikatz_modules.yml (60%) rename dist/ssa/{deprecated => complex}/ssa___applying_stolen_credentials_via_powersploit_modules.yml (60%) rename dist/ssa/{deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml => complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml} (75%) create mode 100644 dist/ssa/complex/ssa___attempt_to_delete_services.yml create mode 100644 dist/ssa/complex/ssa___attempt_to_disable_services.yml create mode 100644 dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml rename dist/ssa/{deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml => complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml} (80%) rename dist/ssa/{deprecated/ssa___credential_extraction_dsinternals_modules.yml => complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml} (81%) rename dist/ssa/{deprecated/ssa___credential_extraction_mimikatz_modules.yml => complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml} (75%) rename dist/ssa/{deprecated/ssa___credential_extraction_powersploit_modules.yml => complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml} (76%) create mode 100644 dist/ssa/complex/ssa___delete_a_net_user.yml create mode 100644 dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml create mode 100644 dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml create mode 100644 dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml create mode 100644 dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml create mode 100644 dist/ssa/complex/ssa___disable_net_user_account.yml create mode 100644 dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml create mode 100644 dist/ssa/complex/ssa___fsutil_zeroing_file.yml create mode 100644 dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml rename dist/ssa/{deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml => complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml} (78%) rename dist/ssa/{deprecated => complex}/ssa___illegal_account_creation_via_powersploit_modules.yml (65%) rename dist/ssa/{deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml => complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml} (78%) rename dist/ssa/{deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml => complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml} (79%) rename dist/ssa/{deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml => complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml} (78%) rename dist/ssa/{deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml => complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml} (78%) rename dist/ssa/{deprecated => complex}/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml (64%) rename dist/ssa/{deprecated => complex}/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml (66%) rename dist/ssa/{deprecated => complex}/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml (67%) rename dist/ssa/{deprecated => complex}/ssa___illegal_service_and_process_control_via_powersploit_modules.yml (67%) create mode 100644 dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml rename dist/ssa/{deprecated => complex}/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml (100%) rename dist/ssa/{deprecated => complex}/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml (61%) rename dist/ssa/{deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml => complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml} (77%) rename dist/ssa/{deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml => complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml} (85%) rename dist/ssa/{deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml => complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml} (80%) rename dist/ssa/{deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml => complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml} (79%) rename dist/ssa/{deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml => complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml} (76%) rename dist/ssa/{deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml => complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml} (79%) rename dist/ssa/{deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml => complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml} (77%) rename dist/ssa/{deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml => complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml} (77%) rename dist/ssa/{deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml => complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml} (79%) rename dist/ssa/{deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml => complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml} (74%) rename dist/ssa/{deprecated/ssa___recon_connectivity_via_powersploit_modules.yml => complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml} (79%) rename dist/ssa/{deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml => complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml} (79%) rename dist/ssa/{deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml => complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml} (76%) rename dist/ssa/{deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml => complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml} (76%) rename dist/ssa/{deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml => complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml} (67%) create mode 100644 dist/ssa/complex/ssa___resize_shadowstorage_volume.yml create mode 100644 dist/ssa/complex/ssa___sdelete_application_execution.yml rename dist/ssa/{deprecated => complex}/ssa___setting_credentials_via_dsinternals_modules.yml (71%) rename dist/ssa/{deprecated => complex}/ssa___setting_credentials_via_mimikatz_modules.yml (66%) rename dist/ssa/{deprecated => complex}/ssa___setting_credentials_via_powersploit_modules.yml (65%) create mode 100644 dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml create mode 100644 dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml create mode 100644 dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml create mode 100644 dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml delete mode 100644 dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml delete mode 100644 dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml delete mode 100644 dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml delete mode 100644 dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml delete mode 100644 dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml delete mode 100644 dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml delete mode 100644 dist/ssa/deprecated/ssa___detect_pass_hash.yml create mode 100644 dist/ssa/srs/ssa___detect_kerberoasting.yml create mode 100644 dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml create mode 100644 dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml create mode 100644 dist/ssa/srs/ssa___high_file_deletion_frequency.yml create mode 100644 dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml create mode 100644 dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml create mode 100644 dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml create mode 100644 dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml create mode 100644 dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml create mode 100644 dist/ssa/srs/ssa___unusually_long_command_line.yml diff --git a/bin/generate.py b/bin/generate.py index 7be0c5eea5..9bca712718 100644 --- a/bin/generate.py +++ b/bin/generate.py @@ -105,10 +105,18 @@ def generate_ssa_yaml(detections, TEMPLATE_PATH, OUTPUT_PATH): yaml.Dumper.ignore_aliases = lambda *args : True # wiping old detections for SSA - shutil.rmtree(OUTPUT_PATH + '/detections/*', ignore_errors=True) + shutil.rmtree(OUTPUT_PATH + '/srs/*', ignore_errors=True) + shutil.rmtree(OUTPUT_PATH + '/complex/*', ignore_errors=True) for d in detections: - manifest_file = OUTPUT_PATH + '/detections/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' + # check if the search contains "stats", "first_time_event", or "adaptive_threshold" which would make it a complex pipeline + pattern = re.compile('stats|first_time_event|adaptive_threshold') + + if re.findall("stats|first_time_event|adaptive_threshold", d['search']): + manifest_file = OUTPUT_PATH + '/complex/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' + print(d['name']) + else: + manifest_file = OUTPUT_PATH + '/srs/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' # remove unused fields del d['risk'] @@ -127,7 +135,7 @@ def generate_ssa_yaml(detections, TEMPLATE_PATH, OUTPUT_PATH): with open(manifest_file, 'w') as file: documents = yaml.dump(d, file, sort_keys=True) - return OUTPUT_PATH + '/detections/' + return True def generate_savedsearches_conf(detections, deployments, TEMPLATE_PATH, OUTPUT_PATH): ''' diff --git a/dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml b/dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml new file mode 100644 index 0000000000..a0716cc96c --- /dev/null +++ b/dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml @@ -0,0 +1,96 @@ +author: Patrick Bareiss, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-22' +description: The following detection identifies the usage of archive tools from the + command line. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. +id: 63614a58-10e2-4c6c-ae81-ea1113681439 +known_false_positives: False positives can be ligitmate usage of archive tools from + the command line. +name: Anomalous usage of Archive Tools +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1560/001/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading + of 7zip. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), + "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), + parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), parent_process=ucast(map_get(input_event, "parent_process"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name + IS NOT NULL AND parent_process_name IS NOT NULL | where like(process_name, "7z%") + OR process_name="WinRAR.exe" OR like(process_name, "winzip%") | where like(parent_process_name, + "%cmd.exe") OR like(parent_process_name, "%powershell.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name", + parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Cobalt Strike + - NOBELIUM Group + confidence: 60 + context: + - Source:Endpoint + - Stage:Collection + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log + impact: 70 + kill_chain_phases: + - Actions on Objective + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading + of 7zip. + mitre_attack_id: + - T1560.001 + - T1560 + observable: + - name: user + role: + - Victim + type: User + - name: dest + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - Processes.process_name + - Processes.process + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + risk_score: 42 + risk_severity: medium + security_domain: endpoint +test: + name: Anomalous usage of Archive Tools Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log + file_name: security.log + source: WinEventLog:Security + description: Test for Anomalous usage of Archive Tools + file: endpoint/ssa___anomalous_usage_of_archive_tools.yml + name: Anomalous usage of Archive Tools + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___applying_stolen_credentials_via_mimikatz_modules.yml similarity index 60% rename from dist/ssa/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___applying_stolen_credentials_via_mimikatz_modules.yml index 1ab52f5e28..c2d7b5f6be 100644 --- a/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___applying_stolen_credentials_via_mimikatz_modules.yml @@ -1,22 +1,43 @@ -name: Applying Stolen Credentials via Mimikatz modules -id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 -version: 2 -date: '2021-11-24' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: The following analytic identifites the use of Mimikatz modules attempting - to perform Pass-the-Ticket, Golden or Silver Kerberos ticket attacks and Skeleton - Key attack. This behavior is typically performed within interactive Mimikatz memory - space, however it may be identified on the command-line. A Pass-the-Ticket (ptt) - attack is performed once an adversary has established access to a single endpoint - and retrieved the kerberos ticket to now begin moving laterally using this method. - Typically, it blends in with logon activity as the ticket can be copied to another - system and passed into the current session effectively simulating a logon without - any communication with the Domain Controller. A Golden or Silver ticket attack requires - some setup by the adversary, but once performed it will simulate lateral based authentication - to additional endpoints. +date: '2021-11-24' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifites the use of Mimikatz modules attempting to perform Pass-the-Ticket, + Golden or Silver Kerberos ticket attacks and Skeleton Key attack. This behavior + is typically performed within interactive Mimikatz memory space, however it may + be identified on the command-line. A Pass-the-Ticket (ptt) attack is performed once + an adversary has established access to a single endpoint and retrieved the kerberos + ticket to now begin moving laterally using this method. Typically, it blends in + with logon activity as the ticket can be copied to another system and passed into + the current session effectively simulating a logon without any communication with + the Domain Controller. A Golden or Silver ticket attack requires some setup by the + adversary, but once performed it will simulate lateral based authentication to additional + endpoints.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to Mimikatz. +name: Applying Stolen Credentials via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +- https://adsecurity.org/?p=1275 +- https://adsecurity.org/?p=1515 +- https://adsecurity.org/?page_id=1821#KERBEROSPTT +- https://attack.mitre.org/software/S0002/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash +risk_message: Mimikatz malware is violating authentication processes by injecting + golden or silver Kerberos tickets or passing stolen authentication tokens. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where @@ -26,19 +47,6 @@ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to Mimikatz. -references: -- https://github.com/gentilkiwi/mimikatz -- https://adsecurity.org/?p=1275 -- https://adsecurity.org/?p=1515 -- https://adsecurity.org/?page_id=1821#KERBEROSPTT -- https://attack.mitre.org/software/S0002/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash tags: analytic_story: - Credential Dumping @@ -81,17 +89,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -103,3 +111,16 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +test: + name: Applying Stolen Credentials via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test applying stolen credentials detections + file: endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml + name: Applying Stolen Credentials via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/complex/ssa___applying_stolen_credentials_via_powersploit_modules.yml similarity index 60% rename from dist/ssa/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___applying_stolen_credentials_via_powersploit_modules.yml index 080e134e90..dacb73b8b0 100644 --- a/dist/ssa/deprecated/ssa___applying_stolen_credentials_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___applying_stolen_credentials_via_powersploit_modules.yml @@ -1,19 +1,36 @@ -name: Applying Stolen Credentials via PowerSploit modules -id: 270b482d-2af2-448f-9923-9cf005f61be4 -version: 2 -date: '2021-11-24' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: The following analytic identifies commonly used PowerSploit modules that - perform credential access, spoofing of authentication processes, user impersonation - and attempting to manipulate tokens. Specifically, the following modules `Invoke-CredentialInjection`, - `Invoke-TokenManipulation`, `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` - were identfiied as modules used to access credentials. PowerSploit is an archived - project on GitHub, but much of its modules and scripts are still utilized today - by adversaries. This behavior is typically performed within interactive PowerShell - sessions or injected into processes, however it may be identified on the command-line. +date: '2021-11-24' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies commonly used PowerSploit modules that perform credential access, + spoofing of authentication processes, user impersonation and attempting to manipulate + tokens. Specifically, the following modules `Invoke-CredentialInjection`, `Invoke-TokenManipulation`, + `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` were identfiied + as modules used to access credentials. PowerSploit is an archived project on GitHub, + but much of its modules and scripts are still utilized today by adversaries. This + behavior is typically performed within interactive PowerShell sessions or injected + into processes, however it may be identified on the command-line.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 270b482d-2af2-448f-9923-9cf005f61be4 +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to PowerSploit. +name: Applying Stolen Credentials via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +- https://attack.mitre.org/software/S0194/ +risk_message: PowerSploit malware is violating authentication by injecting stolen + credentials, manipulating authentication tokens or impersonating system or user + accounts. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -28,15 +45,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to PowerSploit. -references: -- https://github.com/PowerShellMafia/PowerSploit -- https://attack.mitre.org/software/S0194/ tags: analytic_story: - Credential Dumping @@ -76,17 +84,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -98,3 +106,16 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +test: + name: Applying Stolen Credentials via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test applying stolen credentials detections + file: endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml + name: Applying Stolen Credentials via PowerSploit + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml similarity index 75% rename from dist/ssa/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml rename to dist/ssa/complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml index 6fb960b256..81bc5ed977 100644 --- a/dist/ssa/deprecated/ssa___assess_credential_strength_via_dsinternals_modules.yml +++ b/dist/ssa/complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml @@ -1,14 +1,29 @@ -name: Assessment of Credential Strength via DSInternals modules -id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f -version: 2 -date: '2021-11-24' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: The following analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, - that verifies password strength. Adversaries have utilized this module to determine - password complexity or to identify accounts with weak passwords. +date: '2021-11-24' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, that + verifies password strength. Adversaries have utilized this module to determine password + complexity or to identify accounts with weak passwords.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +name: Assessment of Credential Strength via DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +risk_message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. + Account attempting this operation is $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -20,15 +35,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ tags: analytic_story: - Credential Dumping @@ -61,17 +67,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -81,5 +87,7 @@ tags: - dest_user_id - cmd_line risk_score: 25 - risk_severity: high + risk_severity: medium security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/complex/ssa___attempt_to_delete_services.yml b/dist/ssa/complex/ssa___attempt_to_delete_services.yml new file mode 100644 index 0000000000..043cbf7607 --- /dev/null +++ b/dist/ssa/complex/ssa___attempt_to_delete_services.yml @@ -0,0 +1,106 @@ +author: Teoderick Contreras, splunk +datamodel: +- Endpoint_Processes +date: '2021-11-24' +description: The following analytic identifies Windows Service Control, `sc.exe`, + attempting to delete a service. This is typically identified in parallel with other + instances of service enumeration of attempts to stop a service and then delete it. + Adversaries utilize this technique to terminate security services or other related + services to continue there objective and evade detections. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: a0c8c292-d01a-11eb-aa18-acde48001122 +known_false_positives: It is possible administrative scripts may start/stop/delete + services. Filter as needed. +name: Attempt To Delete Services +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%delete%") AND process_name = "sc.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 8 + - CIS 13 + confidence: 60 + context: + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. + mitre_attack_id: + - T1489 + - T1543 + - T1543.003 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 36 + risk_severity: medium + security_domain: endpoint +test: + name: Attempt To delete Services Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log + file_name: sc_del.log + source: WinEventLog:Security + description: Test for usage of sc.exe to delete a service + file: endpoint/ssa___attempt_to_delete_services.yml + name: Attempt To delete Services + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/complex/ssa___attempt_to_disable_services.yml b/dist/ssa/complex/ssa___attempt_to_disable_services.yml new file mode 100644 index 0000000000..869d013f4b --- /dev/null +++ b/dist/ssa/complex/ssa___attempt_to_disable_services.yml @@ -0,0 +1,105 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-24' +description: The following analytic identifies Windows Service Control, `sc.exe`, + attempting to disable a service. This is typically identified in parallel with other + instances of service enumeration of attempts to stop a service and then disable + it. Adversaries utilize this technique to terminate security services or other related + services to continue there objective and evade detections. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: afb31de4-d023-11eb-98d5-acde48001122 +known_false_positives: It is possible administrative scripts may start/stop/delete + services. Filter as needed. +name: Attempt To Disable Services +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. +search: '| from read_ssa_enriched_events() | eval _datamodels=ucast(map_get(input_event, + "_datamodels"), "collection", []), body={} | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%disabled%") AND like(cmd_line, "%config%") + AND process_name="sc.exe" | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 9 + - CIS 8 + confidence: 60 + context: + - Source:Endpoint + - Stage:Privilege Escalation + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. + mitre_attack_id: + - T1489 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + risk_score: 36 + risk_severity: medium + security_domain: endpoint +test: + name: Attempt To Disable Services Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log + file_name: sc_disable.log + source: WinEventLog:Security + description: Test for usage of sc.exe to disable a service + file: endpoint/ssa___attempt_to_disable_services.yml + name: Attempt To Disable Services + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml b/dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml new file mode 100644 index 0000000000..a27a74f132 --- /dev/null +++ b/dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml @@ -0,0 +1,99 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search looks for flags passed to bcdedit.exe modifications to the + built-in Windows error recovery boot configurations. This is typically used by ransomware + to prevent recovery. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13 +known_false_positives: Administrators may modify the boot configuration. +name: BCDEdit Failure Recovery Modification +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability + to recover the endpoint. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bcdedit.exe" + AND (like (cmd_line, "%recoveryenabled%") AND like (cmd_line, "%no%")) | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - Ryuk Ransomware + - Ransomware + cis20: + - CIS 8 + confidence: 80 + context: + - Source:Endpoint + - Stage:Impact + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability + to recover the endpoint. + mitre_attack_id: + - T1490 + nist: + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: BCDEdit Failure Recovery Modification - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + description: Test detection of BCDEdit Failure Recovery Modification + file: endpoint/ssa___bcdedit_failure_recovery_modification.yml + name: BCDEdit Failure Recovery Modification + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml similarity index 80% rename from dist/ssa/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml rename to dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml index e929f5a744..8b64d2eba1 100644 --- a/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_conversion_modules.yml +++ b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml @@ -1,17 +1,33 @@ -name: Credential Extraction indicative of use of DSInternals credential conversion - modules -id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 -version: 2 -date: '2021-11-29' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: The following analytic identifies modules within DSInternals that are - used for extracting credentials from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, - `ConvertFrom-GPPrefPassword`, `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, +date: '2021-11-29' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies modules within DSInternals that are used for extracting credentials + from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, `ConvertFrom-GPPrefPassword`, + `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, `ConvertTo-LMHash`, `ConvertTo-NTHash` `ConvertTo-OrgIdHash` or `ConvertTo-UnicodePassword`. - Adversaries may use these modules for decrypting or transforming the stored credentials. + Adversaries may use these modules for decrypting or transforming the stored credentials.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +name: Credential Extraction indicative of use of DSInternals credential conversion + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +risk_message: DSInternals tool kit is converting stolen credential material to a form + applicable to authentications. Operation is performed on the device $dest_device_id$, + by the account $dest_user_id$ via process $process_name$. search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -31,15 +47,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ tags: analytic_story: - Credential Dumping @@ -69,17 +76,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: process_name - type: process role: - Child Process + type: process product: - Splunk Behavioral Analytics required_fields: @@ -91,5 +98,7 @@ tags: - dest_user_id - cmd_line risk_score: 70 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml similarity index 81% rename from dist/ssa/deprecated/ssa___credential_extraction_dsinternals_modules.yml rename to dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml index 131eca2eec..f45b2993b6 100644 --- a/dist/ssa/deprecated/ssa___credential_extraction_dsinternals_modules.yml +++ b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml @@ -1,14 +1,31 @@ -name: Credential Extraction indicative of use of DSInternals modules -id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d -version: 2 -date: '2021-11-29' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: The following analytic identifies modules of DSInternals being used on - the associated endpoint. Adversaries may use these modules for manipulating data - related to Active Directory and credentials. +date: '2021-11-29' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. The following + analytic identifies modules of DSInternals being used on the associated endpoint. + Adversaries may use these modules for manipulating data related to Active Directory + and credentials.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d +known_false_positives: None identified as this is strictly identifying known command-line + attributes related to DSInternals. +name: Credential Extraction indicative of use of DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +- https://attack.mitre.org/techniques/T1059/001/ +risk_message: DSInternals tool kit is accessing sensitive credential material such + as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via process $process_name$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -30,15 +47,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ tags: analytic_story: - Credential Dumping @@ -69,17 +77,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: process_name - type: Process role: - Child Process + type: Process product: - Splunk Behavioral Analytics required_fields: @@ -92,5 +100,7 @@ tags: - process - cmd_line risk_score: 70 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/deprecated/ssa___credential_extraction_mimikatz_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml similarity index 75% rename from dist/ssa/deprecated/ssa___credential_extraction_mimikatz_modules.yml rename to dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml index 719e5d50f1..152bedd309 100644 --- a/dist/ssa/deprecated/ssa___credential_extraction_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml @@ -1,15 +1,27 @@ -name: Credential Extraction indicative of use of Mimikatz modules -id: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 -version: 1 -date: '2020-10-21' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. Mimikatz - is a collection of tools and modules commonly employed in Windows exploits. +date: '2020-10-21' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. Mimikatz is a collection of tools and modules + commonly employed in Windows exploits.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 +known_false_positives: None identified. +name: Credential Extraction indicative of use of Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is extracting/decoding encoded credentials from stores + such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -26,11 +38,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Credential Dumping @@ -58,17 +65,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -77,5 +84,7 @@ tags: - process - _time risk_score: 66 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___credential_extraction_powersploit_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml similarity index 76% rename from dist/ssa/deprecated/ssa___credential_extraction_powersploit_modules.yml rename to dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml index 04ff3f2af3..e6a8ff148f 100644 --- a/dist/ssa/deprecated/ssa___credential_extraction_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml @@ -1,15 +1,27 @@ -name: Credential Extraction indicative of use of PowerSploit modules -id: 5f1186a4-e681-446e-851c-dc9574ad28eb -version: 1 -date: '2020-10-21' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. PowerSploit - is a collection of Microsoft PowerShell modules commonly employed in exploits. +date: '2020-10-21' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. Credential + extraction is often an illegal recovery of credential material from secured authentication + resources and repositories. This process may also involve decryption or other transformations + of the stored credential material. PowerSploit is a collection of Microsoft PowerShell + modules commonly employed in exploits.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 5f1186a4-e681-446e-851c-dc9574ad28eb +known_false_positives: None identified. +name: Credential Extraction indicative of use of PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is extracting encoded credentials or spoofing automated + logings. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -27,11 +39,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Credential Dumping @@ -59,17 +66,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -78,5 +85,7 @@ tags: - process - _time risk_score: 70 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___delete_a_net_user.yml b/dist/ssa/complex/ssa___delete_a_net_user.yml new file mode 100644 index 0000000000..ba622e4b1c --- /dev/null +++ b/dist/ssa/complex/ssa___delete_a_net_user.yml @@ -0,0 +1,109 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This analytic will detect a suspicious net.exe/net1.exe command-line + to delete a user on a system. This technique may be use by an administrator for + legitimate purposes, however this behavior has been used in the wild to impair some + user or deleting adversaries tracks created during its lateral movement additional + systems. During triage, review parallel processes for additional behavior. Identify + any other user accounts created before or after. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe may be used. +id: 8776d79c-d26e-11eb-9a56-acde48001122 +known_false_positives: System administrators or scripts may delete user accounts via + this technique. Filter as needed. +name: Delete A Net User +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user + account. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" + OR process_name="net.exe") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 4 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log + impact: 70 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user + account. + mitre_attack_id: + - T1531 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 49 + risk_severity: medium + security_domain: endpoint +test: + name: Delete A Net User Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log + file_name: net_user_del.log + source: WinEventLog:Security + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log + file_name: security.log + source: WinEventLog:Security + description: Test for usage of net.exe or net1.exe to delete net user + file: endpoint/ssa___delete_a_net_user.yml + name: Delete A Net User + pass_condition: '@count_gt(0)' +type: Anomaly +version: 3 diff --git a/dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml b/dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml new file mode 100644 index 0000000000..82f434863b --- /dev/null +++ b/dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml @@ -0,0 +1,92 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` + or `xcacls.exe` placing the deny permission on a file or directory. Adversaries + perform this behavior to prevent responders from reviewing or gaining access to + adversary files on disk. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. +id: b76eae28-cd25-11eb-9c92-acde48001122 +known_false_positives: System administrators may use cacls utilities but this is not + a common practice. Filter as needed. +name: Deny Permission using Cacls Utility +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to deny + a permission of a file or directory in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)deny/)=true + AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + cis20: + - CIS 14 + - CIS 16 + confidence: 70 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + impact: 50 + kill_chain_phases: + - Exploitation + message: A cacls process $process_name$ with commandline $cmd_line$ try to deny + a permission of a file or directory in host $dest_device_id$ + mitre_attack_id: + - T1222 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Deny Permission using Cacls Utility Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + file_name: all_icalc.log + source: WinEventLog:Security + description: Test for usage of cacls deny permission to a file(s) or folder(s) + file: endpoint/ssa___deny_permission_using_cacls_utility.yml + name: Deny Permission using Cacls Utility + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml new file mode 100644 index 0000000000..e31f5ae16e --- /dev/null +++ b/dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -0,0 +1,87 @@ +author: Jose Hernandez, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-29' +description: The following analytic identifies credential dumping using comsvcs.dll + with `regsvr32.exe`. This technique is common with adversaries who would like to + dump the memory of lsass.exe and perform offline password cracking. +how_to_implement: You must be ingesting endpoint data that tracks process activity, + including Windows command line logging. You can see how we test this with [Event + Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) + on the [attack_range](https://github.com/splunk/attack_range/blob/develop/ansible/roles/windows_common/tasks/windows-enable-4688-cmd-line-audit.yml). +id: 76bb9e35-f314-4c3d-a385-83c72a13ce4e +known_false_positives: False positives should be limited, filter as needed. +name: Detect Dump LSASS Memory using comsvcs +product: +- Splunk Behavioral Analytics +references: +- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll +risk_message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ + by user $dest_device_user$. +search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_event, + "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), + "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", + null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where process_name LIKE "%rundll32.exe%" AND match_regex(process, + /(?i)comsvcs.dll[,\s]+MiniDump/)=true | eval start_time = timestamp, end_time = + timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, + "process_name", process_name, "process", process]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + asset_type: Endpoint + cis20: + - CIS 8 + - CIS 16 + confidence: 100 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ + by user $dest_device_user$. + mitre_attack_id: + - T1003.003 + - T1003 + nist: + - DE.CM + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _tenant + - _time + - dest_device_id + - process + risk_score: 70 + risk_severity: low + security_domain: endpoint +test: + name: Detect Dump LSASS Memory using comsvcs - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test credential dumping detections + file: endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml + name: Detect Dump LSASS Memory using comsvcs + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml b/dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml new file mode 100644 index 0000000000..f369662145 --- /dev/null +++ b/dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml @@ -0,0 +1,103 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2020-11-10' +description: The following analytic identifies parent processes, browsers, Windows + terminal applications, Office Products and Java spawning cmd.exe. By its very nature, + many applications spawn cmd.exe natively or built into macros. Much of this will + need to be tuned to further enhance the risk. +how_to_implement: In order to successfully implement this analytic, you will need + endpoint process data from a EDR product or Sysmon. This search has been modified + to process raw sysmon data from attack_range's nxlogs on DSP. +id: c10a18cb-fd80-4ffa-a844-25026e0a0c94 +known_false_positives: There are circumstances where an application may legitimately + execute and interact with the Windows command-line interface. +name: Detect Prohibited Applications Spawning cmd exe +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1059/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event + that warrants investigating. +search: '| from read_ssa_enriched_events() + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) + | eval process_name=ucast(map_get(input_event, "process_name"), "string", null), + parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", + null)), cmd_line=lower(ucast(map_get(input_event, "process"),"string", null)), dest_user_id=ucast(map_get(input_event, + "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), + "string", null), event_id=ucast(map_get(input_event,"event_id"), "string", null) + | where process_name="cmd.exe" | rex field=parent_process "(?[^\\\\]+)$" + | where ParentBaseFileName="winword.exe" OR ParentBaseFileName="excel.exe" OR ParentBaseFileName="outlook.exe" + OR ParentBaseFileName="powerpnt.exe" OR ParentBaseFileName="visio.exe" OR ParentBaseFileName="mspub.exe" + OR ParentBaseFileName="acrobat.exe" OR ParentBaseFileName="acrord32.exe" OR ParentBaseFileName="iexplore.exe" + OR ParentBaseFileName="opera.exe" OR ParentBaseFileName="firefox.exe" OR (ParentBaseFileName="java.exe" + AND (cmd_line IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%patch1-Hotfix1a%")))) + OR ParentBaseFileName="powershell.exe" OR (ParentBaseFileName="chrome.exe" AND (cmd_line + IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%chrome-extension%")))) + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, + dest_user_id), body=create_map(["event_id", event_id, "process_name", process_name, + "parent_process_name", parent_process, "cmd_line", cmd_line]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious Command-Line Executions + cis20: + - CIS 8 + confidence: 50 + context: + - Source:Endpoint + - Stage:Defense Evasion + impact: 70 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event + that warrants investigating. + mitre_attack_id: + - T1059 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - parent_process_name + - _time + - dest_device_id + - dest_user_id + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Detect Prohibited Applications Spawning cmd exe Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Detect Prohibited Applications Spawning cmd exe + file: endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml + name: Detect Prohibited Applications Spawning cmd exe + pass_condition: '@count_gt(0)' +type: Anomaly +version: 2 diff --git a/dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml b/dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml new file mode 100644 index 0000000000..effffe33fc --- /dev/null +++ b/dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml @@ -0,0 +1,97 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-03' +description: This analytic identifies commonly used command-line arguments used by + `rclone.exe` to initiate a file transfer. Some arguments were negated as they are + specific to the configuration used by adversaries. In particular, an adversary may + list the files or directories of the remote file share using `ls` or `lsd`, which + is not indicative of malicious behavior. During triage, at this stage of a ransomware + event, exfiltration is about to occur or has already. Isolate the endpoint and continue + investigating by review file modifications and parallel processes. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: e8b74268-5454-11ec-a799-acde48001122 +known_false_positives: False positives should be limited as this is restricted to + the Rclone process name. Filter or tune the analytic as needed. +name: Detect RClone Command-Line Usage +product: +- Splunk Behavioral Analytics +references: +- https://redcanary.com/blog/rclone-mega-extortion/ +- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html +- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ +- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a remote + cloud service to move files or folders. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="rclone.exe" + AND (like (cmd_line, "%copy%") OR like (cmd_line, "%mega%")OR like (cmd_line, "%pcloud%") + OR like (cmd_line, "%ftp%") OR like (cmd_line, "%--config%") OR like (cmd_line, + "%--progress%") OR like (cmd_line, "%--no-check-certificate%") OR like (cmd_line, + "%--ignore-existing%") OR like (cmd_line, "%--auto-confirm%") OR like (cmd_line, + "%--transfers%") OR like (cmd_line, "%--multi-thread-streams%")) | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) + | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - DarkSide Ransomware + - Ransomware + automated_detection_testing: passed + confidence: 70 + context: + - Source:Endpoint + - Stage:Exfiltration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log + impact: 50 + kill_chain_phases: + - Exfiltration + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a + remote cloud service to move files or folders. + mitre_attack_id: + - T1020 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___disable_net_user_account.yml b/dist/ssa/complex/ssa___disable_net_user_account.yml new file mode 100644 index 0000000000..6e179bef39 --- /dev/null +++ b/dist/ssa/complex/ssa___disable_net_user_account.yml @@ -0,0 +1,104 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This analytic will identify a suspicious command-line that disables a + user account using the native `net.exe` or `net1.exe` utility to Windows. This technique + may used by the adversaries to interrupt availability of accounts and continue the + impact against the organization. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be + used. +id: ba858b08-d26c-11eb-af9b-acde48001122 +known_false_positives: System administrators or automated scripts may disable an account + but not a common practice. Filter as needed. +name: Disable Net User Account +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND like(cmd_line, "%user%") + AND (process_name="net1.exe" OR process_name="net.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + - Ransomware + cis20: + - CIS 4 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log + impact: 70 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. + mitre_attack_id: + - T1489 + - T1078 + nist: + - PR.AC + - PR.IP + observable: + - name: user + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 49 + risk_severity: medium + security_domain: endpoint +test: + name: Disable Net User Account Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log + file_name: net_user_dis.log + source: WinEventLog:Security + description: Test for usage of net.exe or net1.exe to disable net user + file: endpoint/ssa___disable_net_user_account.yml + name: Disable Net User Account + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml b/dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml new file mode 100644 index 0000000000..0f154fa153 --- /dev/null +++ b/dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml @@ -0,0 +1,104 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search is to detect potential DNS exfiltration using nslookup application. + This technique are seen in couple of malware and APT group to exfiltrated collected + data in a infected machine or infected network. This detection is looking for unique + use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are + commonly used by attacker and also the retry parameter which is designed to query + C2 DNS multiple tries. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: 2452e632-9e0d-11eb-34ba-acde48001122 +known_false_positives: It is possible for some legitimate administrative utilities + to use similar cmd_line parameters. Filter as needed. +name: DNS Exfiltration Using Nslookup App +product: +- Splunk Behavioral Analytics +references: +- https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html +- https://www.varonis.com/blog/dns-tunneling/ +- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related + to DNS exfiltration. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="nslookup.exe" + AND (like (cmd_line, "%-querytype=%") OR like (cmd_line, "%-qt=%") OR like (cmd_line, + "%-q=%") OR like (cmd_line, "%-type=%") OR like (cmd_line, "%-retry=%")) | eval + start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Suspicious DNS Traffic + - Dynamic DNS + - Command and Control + - Data Exfiltration + automated_detection_testing: passed + confidence: 80 + context: + - Source:Endpoint + - Stage:Exfiltration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related + to DNS exfiltration. + mitre_attack_id: + - T1048 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 72 + risk_severity: low + security_domain: endpoint +test: + name: DNS Exfiltration Using Nslookup App Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + file: endpoint/ssa_dns_exfiltration_using_nslookup_app.yml + name: DNS Exfiltration Using Nslookup App + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___fsutil_zeroing_file.yml b/dist/ssa/complex/ssa___fsutil_zeroing_file.yml new file mode 100644 index 0000000000..0efb8d94cc --- /dev/null +++ b/dist/ssa/complex/ssa___fsutil_zeroing_file.yml @@ -0,0 +1,97 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search is to detect a suspicious fsutil process to zeroing a target + file. This technique was seen in lockbit ransomware where it tries to zero out its + malware path as part of its defense evasion after encrypting the compromised host. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed net.exe may be used. +id: f792cdc9-43ee-4429-a3c0-ffce4fed1a85 +known_false_positives: System administrators or scripts may delete user accounts via + this technique. Filter as needed. +name: Fsutil Zeroing File +product: +- Splunk Behavioral Analytics +references: +- https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/ +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file deletion. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" + AND (like (cmd_line, "%setzerodata%")) | eval start_time=timestamp, end_time=timestamp, + entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, + "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", + cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, + "process_path", process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Ransomware + confidence: 90 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: [] + impact: 60 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file + deletion. + mitre_attack_id: + - T1070 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 54 + risk_severity: low + security_domain: endpoint +test: + name: FSUtil Zeroing File - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + description: Test detection of FSUtil Zeroing File + file: endpoint/ssa___fsutil_zeroing_file.yml + name: FSUtil Zeroing File + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml b/dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml new file mode 100644 index 0000000000..70f10dafc1 --- /dev/null +++ b/dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml @@ -0,0 +1,92 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` + or `xcacls.exe` placing the grant permission on a file or directory. Adversaries + perform this behavior to allow components of their files to run, however it allows + responders to review or gaining access to adversary files on disk. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. +id: c6da561a-cd29-11eb-ae65-acde48001122 +known_false_positives: System administrators may use cacls utilities but this is not + a common practice. Filter as needed. +name: Grant Permission Using Cacls Utility +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to grant + user a permission to a file or directory in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)grant/)=true + AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + cis20: + - CIS 14 + - CIS 16 + confidence: 70 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + impact: 50 + kill_chain_phases: + - Exploitation + message: A cacls process $process_name$ with commandline $cmd_line$ try to grant + user a permission to a file or directory in host $dest_device_id$ + mitre_attack_id: + - T1222 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Grant Permission Using Cacls Utility Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + file_name: all_icalc.log + source: WinEventLog:Security + description: Test for usage of cacls grant permission to a file(s) or folder(s) + file: endpoint/ssa___grant_permission_using_cacls_utility.yml + name: Grant Permission Using Cacls Utility + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml similarity index 78% rename from dist/ssa/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml index fda8390475..341dc81365 100644 --- a/dist/ssa/deprecated/ssa___illegal_access_user_content_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml @@ -1,14 +1,26 @@ -name: Illegal Access To User Content via PowerSploit modules -id: 01fc7d91-eb0c-478e-8633-e4fa4904463a -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that enable illegaly - access user content, such as key logging, audio recording, screenshots, tapping - into http and RDP sessions, etc. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that enable illegaly access user content, + such as key logging, audio recording, screenshots, tapping into http and RDP sessions, + etc.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 01fc7d91-eb0c-478e-8633-e4fa4904463a +known_false_positives: None identified. +name: Illegal Access To User Content via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is tapping into user content - microphone, camera, + ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -23,11 +35,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Malicious PowerShell @@ -60,17 +67,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -81,3 +88,5 @@ tags: risk_score: 85 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_account_creation_via_powersploit_modules.yml similarity index 65% rename from dist/ssa/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___illegal_account_creation_via_powersploit_modules.yml index 08bb1ad9fc..97237df015 100644 --- a/dist/ssa/deprecated/ssa___illegal_account_creation_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___illegal_account_creation_via_powersploit_modules.yml @@ -1,13 +1,24 @@ -name: Illegal Account Creation via PowerSploit modules -id: 20fba62a-fa5b-46cc-b39f-473fa248fee2 -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that create accounts - illegaly. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that create accounts illegaly.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 20fba62a-fa5b-46cc-b39f-473fa248fee2 +known_false_positives: None identified. +name: Illegal Account Creation via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is creating illegal domain accounts. Operation is + performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +30,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Persistence Techniques @@ -51,17 +57,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -72,3 +78,16 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +test: + name: Illegal Account Creation via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test illegal account creation detections + file: endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml + name: Illegal Account Creation via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml similarity index 78% rename from dist/ssa/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml index 24be672979..aa16051c53 100644 --- a/dist/ssa/deprecated/ssa___illegal_log_deletion_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml @@ -1,13 +1,24 @@ -name: Illegal Deletion of Logs via Mimikatz modules -id: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that delete event - logs. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that delete event logs.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b +known_false_positives: None identified. +name: Illegal Deletion of Logs via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is deleting event logs to cover tracks of malicious + activity. Operation is performed at the device $dest_device_id$, by the account + $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +30,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Log Manipulation @@ -52,17 +58,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -71,5 +77,7 @@ tags: - process - _time risk_score: 50 - risk_severity: high + risk_severity: medium security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml similarity index 79% rename from dist/ssa/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml rename to dist/ssa/complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml index afdf84bcac..4d6a3d0141 100644 --- a/dist/ssa/deprecated/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml +++ b/dist/ssa/complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml @@ -1,13 +1,24 @@ -name: Illegal Enabling or Disabling of Accounts via DSInternals modules -id: 3e0f9962-9989-445f-878c-939443326b63 -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of DSInternals modules that enable or disable - accounts illegaly. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of DSInternals modules that enable or disable accounts illegaly.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 3e0f9962-9989-445f-878c-939443326b63 +known_false_positives: None identified. +name: Illegal Enabling or Disabling of Accounts via DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +risk_message: DSInternals malware is illegally enabling or disabling accounts. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -20,11 +31,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/MichaelGrafnetter/DSInternals tags: analytic_story: - Windows Persistence Techniques @@ -54,17 +60,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -75,3 +81,5 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml similarity index 78% rename from dist/ssa/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml rename to dist/ssa/complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml index 85fa7639e5..0b45aa84ef 100644 --- a/dist/ssa/deprecated/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml +++ b/dist/ssa/complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml @@ -1,14 +1,26 @@ -name: Illegal Management of Active Directory Elements and Policies via DSInternals - modules -id: a587ca9f-c138-47b4-ba51-699f319b8cc5 -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of DSInternals modules for illegal management - of Active Directoty elements and policies. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of DSInternals modules for illegal management of Active Directoty + elements and policies.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: a587ca9f-c138-47b4-ba51-699f319b8cc5 +known_false_positives: None identified. +name: Illegal Management of Active Directory Elements and Policies via DSInternals + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +risk_message: DSInternals malware is controlling infrastructure by modifying Active + Directory elements, domain controllers, and policies. Operation is performed at + the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -22,11 +34,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/MichaelGrafnetter/DSInternals tags: analytic_story: - Windows Persistence Techniques @@ -57,17 +64,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -78,3 +85,5 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml similarity index 78% rename from dist/ssa/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml index 3a54457131..12c1053ff5 100644 --- a/dist/ssa/deprecated/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml @@ -1,14 +1,26 @@ -name: Illegal Management of Computers and Active Directory Elements via PowerSploit - modules -id: 75760c11-7d48-4968-b828-013b299e8f6d -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that enable illegal - management of computers and Active Directory elements. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that enable illegal management of computers + and Active Directory elements.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 75760c11-7d48-4968-b828-013b299e8f6d +known_false_positives: None identified. +name: Illegal Management of Computers and Active Directory Elements via PowerSploit + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is controlling infrastructure by modifying Active + Directory elements or local Master Boot Records. Operation is performed at the device + $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -23,11 +35,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Persistence Techniques @@ -58,17 +65,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -79,3 +86,5 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml similarity index 64% rename from dist/ssa/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml index 254a2292a9..6ec2973e83 100644 --- a/dist/ssa/deprecated/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml @@ -1,14 +1,26 @@ -name: Illegal Privilege Elevation and Persistence via PowerSploit modules -id: 88c10ee9-fe72-4bce-b343-5b129044b991 -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that illegaly - elevate general privileges or ensure persistence, e.g., enable manipulation of registry, - task scheduling, persistent WMI, access to OS objects under desired identities. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that illegaly elevate general privileges + or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent + WMI, access to OS objects under desired identities.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 88c10ee9-fe72-4bce-b343-5b129044b991 +known_false_positives: None identified. +name: Illegal Privilege Elevation and Persistence via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is planting attack persistence elements, altering + privileges and access controls. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -22,11 +34,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Malicious PowerShell @@ -60,17 +67,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -81,3 +88,17 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +test: + name: Illegal Privilege Elevation and Persistence via PowerSploit modules - SSA + Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test privilege elevation and persistence detections + file: endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml + name: Illegal Privilege Elevation and Persistence via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml similarity index 66% rename from dist/ssa/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml index 54f6aec7bb..14b98b6333 100644 --- a/dist/ssa/deprecated/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml @@ -1,13 +1,24 @@ -name: Illegal Privilege Elevation via Mimikatz modules -id: 2f873b1f-6352-4844-b7b9-b419f09a42c7 -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of Mimikatz modules for illegal privilege - elevation. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for illegal privilege elevation.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 2f873b1f-6352-4844-b7b9-b419f09a42c7 +known_false_positives: None identified. +name: Illegal Privilege Elevation via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is setting highest privileges to malicious entities. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -20,11 +31,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Privilege Escalation @@ -55,17 +61,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -76,3 +82,16 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +test: + name: Illegal Privilege Elevation via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test illegal privilege elevation detections + file: endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml + name: Illegal Privilege Elevation via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml similarity index 67% rename from dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml index c94e7c2c1f..65e6678eaa 100644 --- a/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml @@ -1,13 +1,25 @@ -name: Illegal Service and Process Control via Mimikatz modules -id: aaf3adf1-73e1-4477-b4ee-3771898964f1 -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of Mimikatz modules for illegal control - over services and processes, including the authentication service. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for illegal control over services and processes, + including the authentication service.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: aaf3adf1-73e1-4477-b4ee-3771898964f1 +known_false_positives: None identified. +name: Illegal Service and Process Control via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is controlling computer's processess and services. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -22,11 +34,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Service Abuse @@ -57,17 +64,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -78,3 +85,16 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +test: + name: Illegal Service and Process Control via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test illegal service and process control detections + file: endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml + name: Illegal Service and Process Control via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_service_and_process_control_via_powersploit_modules.yml similarity index 67% rename from dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___illegal_service_and_process_control_via_powersploit_modules.yml index 835cbc4e6c..6766a7231c 100644 --- a/dist/ssa/deprecated/ssa___illegal_service_and_process_control_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___illegal_service_and_process_control_via_powersploit_modules.yml @@ -1,15 +1,27 @@ -name: Illegal Service and Process Control via PowerSploit modules -id: 0e910e5b-309d-4bc3-8af2-0030c02aa353 -version: 1 -date: '2020-11-09' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that enable illegal - control of services and processes, such as installing or spoofing of malicious services, - injecting malicious code in DLLs and EXEs, invoking shell code and WMI commands, - modifying access to service objects, etc. +date: '2020-11-09' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that enable illegal control of services + and processes, such as installing or spoofing of malicious services, injecting malicious + code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to + service objects, etc.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 0e910e5b-309d-4bc3-8af2-0030c02aa353 +known_false_positives: None identified. +name: Illegal Service and Process Control via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is controlling computer's processess and services. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -31,11 +43,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Service Abuse @@ -67,17 +74,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -88,3 +95,16 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +test: + name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test illegal service and process control detections + file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml + name: Illegal Service and Process Control via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml b/dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml new file mode 100644 index 0000000000..ae2e490edf --- /dev/null +++ b/dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml @@ -0,0 +1,96 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This analytic identifies suspicious modification of ACL permission to + a files or folder to make it available to everyone or to a specific user. This technique + may be used by the adversary to evade ACLs or protected files access. This changes + is commonly configured by the file or directory owner with appropriate permission. + This behavior raises suspicion if this command is seen on an endpoint utilized by + an account with no permission to do so. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. +id: 9ae9a48a-cdbe-11eb-875a-acde48001122 +known_false_positives: System administrators may use this windows utility. filter + is needed. +name: Modify ACLs Permission Of Files Or Folders +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to modify + a permission of a file or directory in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, + "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), + "string", null) | where cmd_line IS NOT NULL AND like(cmd_line, "%/G%") AND (match_regex(cmd_line, + /(?i)everyone:/)=true OR match_regex(cmd_line, /(?i)SYSTEM:/)=true) AND (process_name="cacls.exe" + OR process_name="xcacls.exe" OR process_name="icacls.exe") | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - XMRig + cis20: + - CIS 8 + - CIS 13 + confidence: 70 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + impact: 50 + kill_chain_phases: + - Exploitation + message: A cacls process $process_name$ with commandline $cmd_line$ try to modify + a permission of a file or directory in host $dest_device_id$ + mitre_attack_id: + - T1222 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 35 + risk_severity: medium + security_domain: endpoint +test: + name: Modify ACLs Permission Of Files Or Folders Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log + file_name: all_icalc.log + source: WinEventLog:Security + description: Test for modifying permission of a file(s) or folder(s) using cacls + utility. + file: endpoint/ssa___modify_acls_permission_of_files_or_folders.yml + name: Modify ACLs Permission Of Files Or Folders + pass_condition: '@count_gt(0)' +type: Anomaly +version: 2 diff --git a/dist/ssa/deprecated/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml b/dist/ssa/complex/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml similarity index 100% rename from dist/ssa/deprecated/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml rename to dist/ssa/complex/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml diff --git a/dist/ssa/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/complex/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml similarity index 61% rename from dist/ssa/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml index afcded581a..a7053b9879 100644 --- a/dist/ssa/deprecated/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml @@ -1,13 +1,25 @@ -name: Probing Access with Stolen Credentials via PowerSploit modules -id: d405af5d-99f1-45af-8dfb-b8f98b764247 -version: 1 -date: '2020-11-04' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of PowerSploit modules that facilitate - access probing with admin credentials as well as probing access to system services. +date: '2020-11-04' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules that facilitate access probing with admin + credentials as well as probing access to system services.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: d405af5d-99f1-45af-8dfb-b8f98b764247 +known_false_positives: None identified. +name: Probing Access with Stolen Credentials via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is probing access with stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -20,11 +32,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Privilege Escalation @@ -52,17 +59,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -71,5 +78,19 @@ tags: - dest_user_id - dest_device_id risk_score: 60 - risk_severity: high + risk_severity: low security_domain: endpoint +test: + name: Probing Access with Stolen Credentials via PowerSploit modules - SSA Unit + test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test access probing with stolen credentials detections + file: endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml + name: Probing Access with Stolen Credentials via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml similarity index 77% rename from dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml index 96ee3261f0..af78d4cb23 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml @@ -1,13 +1,25 @@ -name: Reconnaissance and Access to Accounts and Groups via Mimikatz modules -id: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 -version: 1 -date: '2020-11-05' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of Mimikatz modules for discovery of accounts - and groups and access to them. +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery of accounts and groups and access + to them.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 +known_false_positives: None identified. +name: Reconnaissance and Access to Accounts and Groups via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is searching for and using specific accounts and groups. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +31,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Discovery Techniques @@ -53,17 +60,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -74,3 +81,5 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml similarity index 85% rename from dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml index e49bc3b415..48aac644b9 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml @@ -1,13 +1,26 @@ -name: Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules -id: 63422f8e-766c-468f-8133-2ba6795e263b -version: 1 -date: '2020-11-05' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that discover - accounts, groups and policies that can be accessed or taken over. +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover accounts, groups and policies + that can be accessed or taken over.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 63422f8e-766c-468f-8133-2ba6795e263b +known_false_positives: None identified. +name: Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for and using specific accounts, groups + and policies, such as the last logged on account, a local Net group, etc. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -41,11 +54,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -76,17 +84,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -97,3 +105,5 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml similarity index 80% rename from dist/ssa/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml index c711912309..9cd26d09f7 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml @@ -1,15 +1,27 @@ -name: Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit - modules -id: db08ac40-ee14-43e9-9a75-dddd059ef812 -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules for reconnaissance - and access to elements of Active Directory infrastructure, such as domain identifiers, - AD sites and forests, and trust relations. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules for reconnaissance and access to elements + of Active Directory infrastructure, such as domain identifiers, AD sites and forests, + and trust relations.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: db08ac40-ee14-43e9-9a75-dddd059ef812 +known_false_positives: None identified. +name: Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit + modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is seaching for or accessing Active Directory objects + such as domain sites, domain trusts, AD forests, etc. Operation is performed at + the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -30,11 +42,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -66,17 +73,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -87,3 +94,5 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml similarity index 79% rename from dist/ssa/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml index 06fa9a94cf..9f677b78bb 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_computers_domains_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml @@ -1,13 +1,25 @@ -name: Reconnaissance and Access to Computers and Domains via PowerSploit modules -id: fe1c4c5a-09f3-4b43-8129-560a7f38a08b -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that discover - computers, servers and domains that can be accessed or taken over. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover computers, servers and domains + that can be accessed or taken over.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: fe1c4c5a-09f3-4b43-8129-560a7f38a08b +known_false_positives: None identified. +name: Reconnaissance and Access to Computers and Domains via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is seaching for or accessing domain controllers, + computers, file servers, etc. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -24,11 +36,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -58,17 +65,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -79,3 +86,5 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml similarity index 76% rename from dist/ssa/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml index 4de51aecc6..4efdb3ecff 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_computers_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml @@ -1,13 +1,25 @@ -name: Reconnaissance and Access to Computers via Mimikatz modules -id: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of Mimikatz modules for discovery of computers - and servers and access to them. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery of computers and servers and access + to them.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 +known_false_positives: None identified. +name: Reconnaissance and Access to Computers via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is collecting information about computers. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +31,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Discovery Techniques @@ -49,17 +56,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -68,5 +75,7 @@ tags: - dest_device_id - dest_user_id risk_score: 50 - risk_severity: high + risk_severity: medium security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml similarity index 79% rename from dist/ssa/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml index 4f32e0a43a..1637bfac4c 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml @@ -1,14 +1,26 @@ -name: Reconnaissance and Access to Operating System Elements via PowerSploit modules -id: c1d33ad9-1727-4f9f-a474-4adbe4fed68a -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that discover - and access operating system elements, such as processes, services, registry locations, - security packages and files. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover and access operating system + elements, such as processes, services, registry locations, security packages and + files.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: c1d33ad9-1727-4f9f-a474-4adbe4fed68a +known_false_positives: None identified. +name: Reconnaissance and Access to Operating System Elements via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for and tapping into ongoing processes, + mounted drives or other operating system elements. Operation is performed at the + device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -26,11 +38,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -66,17 +73,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -87,3 +94,5 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml similarity index 77% rename from dist/ssa/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml index 6f4d2c9603..cc69c9c467 100644 --- a/dist/ssa/deprecated/ssa___recon_processes_and_services_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml @@ -1,13 +1,23 @@ -name: Reconnaissance and Access to Processes and Services via Mimikatz modules -id: 0243d37c-57c1-4182-bfd1-39b212255fc8 -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of Mimikatz modules for discovery and access - to services and processes. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery and access to services and processes.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 0243d37c-57c1-4182-bfd1-39b212255fc8 +known_false_positives: None identified. +name: Reconnaissance and Access to Processes and Services via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is listing processes and services. Operation is performed + at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +29,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Discovery Techniques @@ -50,17 +55,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -69,5 +74,7 @@ tags: - dest_device_id - dest_user_id risk_score: 50 - risk_severity: high + risk_severity: medium security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml similarity index 77% rename from dist/ssa/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml index 87194d38a9..4ea264cc5b 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_shares_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml @@ -1,13 +1,24 @@ -name: Reconnaissance and Access to Shared Resources via Mimikatz modules -id: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of Mimikatz modules for discovery and access - to network shares. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery and access to network shares.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f +known_false_positives: None identified. +name: Reconnaissance and Access to Shared Resources via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +30,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Discovery Techniques @@ -54,17 +60,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -73,5 +79,7 @@ tags: - dest_device_id - dest_user_id risk_score: 70 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml similarity index 79% rename from dist/ssa/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml index ef1f07cc20..dd4633a38e 100644 --- a/dist/ssa/deprecated/ssa___recon_and_use_shares_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml @@ -1,13 +1,25 @@ -name: Reconnaissance and Access to Shared Resources via PowerSploit modules -id: 6b7ca431-6b1e-4b40-9589-21cb368e369e -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules that discover - and access network and distributed file system shares. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules that discover and access network and distributed + file system shares.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 6b7ca431-6b1e-4b40-9589-21cb368e369e +known_false_positives: None identified. +name: Reconnaissance and Access to Shared Resources via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for and accessing network shares. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -23,11 +35,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -58,17 +65,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -77,5 +84,7 @@ tags: - dest_device_id - dest_user_id risk_score: 70 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml similarity index 74% rename from dist/ssa/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml index e6238d3e36..c79a306b71 100644 --- a/dist/ssa/deprecated/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml @@ -1,16 +1,29 @@ -name: Reconnaissance of Access and Persistence Opportunities via PowerSploit modules -id: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 -version: 1 -date: '2020-11-05' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of PowerSploit modules that discover opportunities - for malicious access and persistence. Some examples include access to admin accounts, - weak access control policies, landing paths for dropping malicious software or data - to exfiltrate, registry locations to land autorun parameters, task scheduling opportunities, - as well as services and system files that can be compromised. +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules that discover opportunities for malicious + access and persistence. Some examples include access to admin accounts, weak access + control policies, landing paths for dropping malicious software or data to exfiltrate, + registry locations to land autorun parameters, task scheduling opportunities, as + well as services and system files that can be compromised.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 +known_false_positives: None identified. +name: Reconnaissance of Access and Persistence Opportunities via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is searching for an entry point into the infrastructure, + such as local admin accounts, opportunities to hijack processes, unattended install + files, or modifiable access objects. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -32,11 +45,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -68,17 +76,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -87,5 +95,7 @@ tags: - dest_device_id - dest_user_id risk_score: 60 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml similarity index 79% rename from dist/ssa/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml index 1a656d9570..4011dcfffe 100644 --- a/dist/ssa/deprecated/ssa___recon_connectivity_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml @@ -1,13 +1,25 @@ -name: Reconnaissance of Connectivity via PowerSploit modules -id: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 -version: 1 -date: '2020-11-06' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies access to PowerSploit modules for reconnaissance - of connectivity. +date: '2020-11-06' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies access to PowerSploit modules for reconnaissance of connectivity.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 +known_false_positives: None identified. +name: Reconnaissance of Connectivity via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is performing port scans or searching for various + connectivity details such as DNS data, proxies, or ongoing RDP connections. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -25,11 +37,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -58,17 +65,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -77,5 +84,7 @@ tags: - dest_device_id - dest_user_id risk_score: 70 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml similarity index 79% rename from dist/ssa/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml index a6fdc66b33..cbfc35bd95 100644 --- a/dist/ssa/deprecated/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml @@ -1,13 +1,25 @@ -name: Reconnaissance of Credential Stores and Services via Mimikatz modules -id: 5facee5b-79e4-47ab-b0e6-c625acc0554f -version: 1 -date: '2020-11-03' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies reconnaissance of credential stores and use - of CryptoAPI services by Mimikatz modules. +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies reconnaissance of credential stores and use of CryptoAPI services by + Mimikatz modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 5facee5b-79e4-47ab-b0e6-c625acc0554f +known_false_positives: None identified. +name: Reconnaissance of Credential Stores and Services via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is searching for and accessing credential stores. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -21,11 +33,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Discovery Techniques @@ -59,17 +66,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -80,3 +87,5 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml similarity index 76% rename from dist/ssa/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml index 94908b1186..c100454874 100644 --- a/dist/ssa/deprecated/ssa___recon_defensive_tools_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml @@ -1,13 +1,24 @@ -name: Reconnaissance of Defensive Tools via PowerSploit modules -id: 24b4e659-63a2-4e7b-89ac-87dd659c7110 -version: 1 -date: '2020-11-05' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of PowerSploit modules for assessment of - presence of defensive tools. +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules for assessment of presence of defensive tools.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 24b4e659-63a2-4e7b-89ac-87dd659c7110 +known_false_positives: None identified. +name: Reconnaissance of Defensive Tools via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is looking for presence of anti virus software. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +30,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -52,17 +58,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -71,5 +77,7 @@ tags: - dest_device_id - dest_user_id risk_score: 40 - risk_severity: high + risk_severity: medium security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml similarity index 76% rename from dist/ssa/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml index 4c2ae2cd99..a919f28981 100644 --- a/dist/ssa/deprecated/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml @@ -1,13 +1,24 @@ -name: Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules -id: b9b4492c-2af8-449b-beb4-b1b78d963321 -version: 1 -date: '2020-11-05' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of PowerSploit modules for assessment of - privilege escalation opportunities. +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of PowerSploit modules for assessment of privilege escalation opportunities.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: b9b4492c-2af8-449b-beb4-b1b78d963321 +known_false_positives: None identified. +name: Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is engaging its privilege escalation module. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +30,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Discovery Techniques @@ -51,17 +57,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -70,5 +76,7 @@ tags: - dest_device_id - dest_user_id risk_score: 60 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml similarity index 67% rename from dist/ssa/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml index 86f058a343..0232e39486 100644 --- a/dist/ssa/deprecated/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml @@ -1,17 +1,30 @@ -name: Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules -id: fc5c1cbd-7494-4314-aad2-458d6fd4fada -version: 1 -date: '2020-11-05' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies use of Mimikatz modules for discovery of process - or service hijacking opportunities via Microsoft Detours compatibility. Microsoft - Detours is an open source library for intercepting, monitoring and instrumenting - binary functions on Microsoft Windows. Detours intercepts Win32 functions by re-writing - the in-memory code for target functions. The Detours package also contains utilities - to attach arbitrary DLLs and data segments called payloads to any Win32 binary. +date: '2020-11-05' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies use of Mimikatz modules for discovery of process or service hijacking + opportunities via Microsoft Detours compatibility. Microsoft Detours is an open + source library for intercepting, monitoring and instrumenting binary functions on + Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory + code for target functions. The Detours package also contains utilities to attach + arbitrary DLLs and data segments called payloads to any Win32 binary.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: fc5c1cbd-7494-4314-aad2-458d6fd4fada +known_false_positives: None identified. +name: Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +- https://en.wikipedia.org/wiki/Microsoft_Detours +risk_message: Mimikatz malware is looking for and invoking Microsoft Detours package + that enables spoofing of in-memory code. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -23,12 +36,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz -- https://en.wikipedia.org/wiki/Microsoft_Detours tags: analytic_story: - Windows Discovery Techniques @@ -58,17 +65,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -77,5 +84,7 @@ tags: - dest_device_id - dest_user_id risk_score: 70 - risk_severity: high + risk_severity: low security_domain: endpoint +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___resize_shadowstorage_volume.yml b/dist/ssa/complex/ssa___resize_shadowstorage_volume.yml new file mode 100644 index 0000000000..aeb81926a4 --- /dev/null +++ b/dist/ssa/complex/ssa___resize_shadowstorage_volume.yml @@ -0,0 +1,105 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: The following analytic identifies the resizing of shadowstorage using + vssadmin.exe to avoid the shadow volumes being made again. This technique is typically + found used by adversaries during a ransomware event and a precursor to deleting + the shadowstorage. +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: dbc30554-d27e-11eb-9e5e-acde48001122 +known_false_positives: System administrators may resize the shadowstorage for valid + purposes. Filter as needed. +name: Resize Shadowstorage Volume +product: +- Splunk Behavioral Analytics +references: +- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html +- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow + copy to perform offline password cracking. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND like(cmd_line, "%resize%") AND like(cmd_line, "%shadowstorage%") + AND like(cmd_line, "%maxsize%") AND process_name="vssadmin.exe" | eval start_time=timestamp, + end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), + "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), + body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, + "parent_process_name", parent_process_name, "process_path", process_path]) | into + write_ssa_detected_events();' +tags: + analytic_story: + - Clop Ransomware + - Ransomware + cis20: + - CIS 10 + - CIS 13 + confidence: 80 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log + impact: 80 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow + copy to perform offline password cracking. + mitre_attack_id: + - T1489 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 64 + risk_severity: low + security_domain: endpoint +test: + name: Resize Shadowstorage Volume Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test for resizing the shadow storage of a machine + file: endpoint/ssa___resize_shadowstorage_volume.yml + name: Resize Shadowstorage Volume + pass_condition: '@count_gt(0)' +type: TTP +version: 3 diff --git a/dist/ssa/complex/ssa___sdelete_application_execution.yml b/dist/ssa/complex/ssa___sdelete_application_execution.yml new file mode 100644 index 0000000000..53541e83fe --- /dev/null +++ b/dist/ssa/complex/ssa___sdelete_application_execution.yml @@ -0,0 +1,110 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-15' +description: This analytic will detect the execution of sdelete.exe attempting to + delete potentially important files that may related to adversary or insider threats + to destroy evidence or information sabotage. Sdelete is a SysInternals utility meant + to securely delete files on disk. This tool is commonly used to clear tracks and + artifact on the targeted host. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +id: fcc52b9a-4616-11ec-8454-acde48001122 +known_false_positives: False positives should be limited, filter as needed. +name: Sdelete Application Execution +product: +- Splunk Behavioral Analytics +references: +- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md +risk_message: Sdelete process $process_name$ executed on $dest_device_id$ attempting + to permanently delete files by $dest_user_id$. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), + "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", + null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), + parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), parent_cmd_line=ucast(map_get(input_event, "parent_process"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line + IS NOT NULL AND process_name IS NOT NULL AND like(process_name, "%sdelete%") AND + (like (cmd_line, "%-c %") OR like (cmd_line, "%-f %")OR like (cmd_line, "%-p %") + OR like (cmd_line, "%-r %") OR like (cmd_line, "%-q %") OR like (cmd_line, "%-s + %") OR like (cmd_line, "%-z %") OR like (cmd_line, "%/accepteula%") OR like (cmd_line, + "%-nobanner%")OR like (cmd_line, "%.doc%")OR like (cmd_line, "%.xls%") OR like (cmd_line, + "%.ppt%")OR like (cmd_line, "%.rtf%") OR like (cmd_line, "%.pdf%") OR like (cmd_line, + "%.key%")OR like (cmd_line, "%.log%") OR like (cmd_line, "%.txt%") OR like (cmd_line, + "%.jpg%") OR like (cmd_line, "%.png%") OR like (cmd_line, "%.gif%") OR like (cmd_line, + "%.bmp%") OR like (cmd_line, "%.7z%") OR like (cmd_line, "%.zip%") OR like (cmd_line, + "%.rar%") OR like (cmd_line, "%.tar%") OR like (cmd_line, "%.gz%") OR like (cmd_line, + "%.xls%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "process_path", process_path, "parent_process_name", parent_process_name, + "parent_cmd_line", parent_cmd_line]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Information Sabotage + confidence: 70 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log + impact: 60 + kill_chain_phases: + - Exploitation + message: Sdelete process $process_name$ executed on $dest_device_id$ attempting + to permanently delete files by $dest_user_id$. + mitre_attack_id: + - T1485 + - T1070.004 + - T1070 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest + - user + - parent_process_name + - parent_process + - process_name + - process + - process_id + - process_path + - cmd_line + risk_score: 42 + risk_severity: medium + security_domain: endpoint +test: + name: Sdelete Application Execution Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log + file_name: security.log + source: WinEventLog:Security + description: Test for sdelete execution command + file: endpoint/ssa___sdelete_application_execution.yml + name: Sdelete Application Execution + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___setting_credentials_via_dsinternals_modules.yml similarity index 71% rename from dist/ssa/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml rename to dist/ssa/complex/ssa___setting_credentials_via_dsinternals_modules.yml index e8c8223525..f91f7f5062 100644 --- a/dist/ssa/deprecated/ssa___setting_credentials_via_dsinternals_modules.yml +++ b/dist/ssa/complex/ssa___setting_credentials_via_dsinternals_modules.yml @@ -1,13 +1,24 @@ -name: Setting Credentials via DSInternals modules -id: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c -version: 1 -date: '2020-11-03' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies illegal setting of credentials via DSInternals - modules. +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies illegal setting of credentials via DSInternals modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c +known_false_positives: None identified. +name: Setting Credentials via DSInternals modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/MichaelGrafnetter/DSInternals +risk_message: DSInternals malware is accessing, using or setting Active Directory + or Azure credentials and accounts. Operation is performed at the device $dest_device_id$, + by the account $dest_user_id$ via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -25,11 +36,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/MichaelGrafnetter/DSInternals tags: analytic_story: - Windows Persistence Techniques @@ -61,17 +67,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -85,3 +91,16 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +test: + name: Setting Credentials via DSInternals modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + file_name: logAllDSInternalsModules.log + source: WinEventLog:Security + description: Test illegal credential setting detections + file: endpoint/ssa___setting_credentials_via_dsinternals_modules.yml + name: Setting Credentials via DSInternals modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___setting_credentials_via_mimikatz_modules.yml similarity index 66% rename from dist/ssa/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml rename to dist/ssa/complex/ssa___setting_credentials_via_mimikatz_modules.yml index 1499f30134..f2771dd531 100644 --- a/dist/ssa/deprecated/ssa___setting_credentials_via_mimikatz_modules.yml +++ b/dist/ssa/complex/ssa___setting_credentials_via_mimikatz_modules.yml @@ -1,13 +1,24 @@ -name: Setting Credentials via Mimikatz modules -id: c8b84699-7652-4363-910f-efd1ca82f780 -version: 1 -date: '2020-11-03' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies illegal setting of credentials via Mimikatz - modules. +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies illegal setting of credentials via Mimikatz modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: c8b84699-7652-4363-910f-efd1ca82f780 +known_false_positives: None identified. +name: Setting Credentials via Mimikatz modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/gentilkiwi/mimikatz +risk_message: Mimikatz malware is accessing, using or setting account credentials. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +30,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/gentilkiwi/mimikatz tags: analytic_story: - Windows Persistence Techniques @@ -54,17 +60,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -75,3 +81,16 @@ tags: risk_score: 80 risk_severity: high security_domain: endpoint +test: + name: Setting Credentials via Mimikatz modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + file_name: logAllMimikatzModules.log + source: WinEventLog:Security + description: Test illegal credential setting detections + file: endpoint/ssa___setting_credentials_via_mimikatz_modules.yml + name: Setting Credentials via Mimikatz modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___setting_credentials_via_powersploit_modules.yml b/dist/ssa/complex/ssa___setting_credentials_via_powersploit_modules.yml similarity index 65% rename from dist/ssa/deprecated/ssa___setting_credentials_via_powersploit_modules.yml rename to dist/ssa/complex/ssa___setting_credentials_via_powersploit_modules.yml index caaf182457..2cfe008d54 100644 --- a/dist/ssa/deprecated/ssa___setting_credentials_via_powersploit_modules.yml +++ b/dist/ssa/complex/ssa___setting_credentials_via_powersploit_modules.yml @@ -1,13 +1,24 @@ -name: Setting Credentials via PowerSploit modules -id: 07b2a501-f967-4ddc-9f56-2dce46dfce44 -version: 1 -date: '2020-11-03' author: Stanislav Miskovic, Splunk -type: TTP datamodel: - Endpoint_Processes -description: This detection identifies illegal setting of credentials via PowerSploit - modules. +date: '2020-11-03' +deprecated: true +description: 'WARNING, this detection has been marked deprecated by the Splunk Threat + Research team, this means that it will no longer be maintained or supported. If + you have any questions feel free to email us at: research@splunk.com. This detection + identifies illegal setting of credentials via PowerSploit modules.' +how_to_implement: You must be ingesting Windows Security logs from devices of interest, + including the event ID 4688 with enabled command line logging. +id: 07b2a501-f967-4ddc-9f56-2dce46dfce44 +known_false_positives: None identified. +name: Setting Credentials via PowerSploit modules +product: +- Splunk Behavioral Analytics +references: +- https://github.com/PowerShellMafia/PowerSploit +risk_message: PowerSploit malware is setting passwords on Active Directory accounts. + Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ + via command $cmd_line$ search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), @@ -19,11 +30,6 @@ search: '| from read_ssa_enriched_events() "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: -- https://github.com/PowerShellMafia/PowerSploit tags: analytic_story: - Windows Persistence Techniques @@ -54,17 +60,17 @@ tags: - PR.IP observable: - name: dest_user_id - type: User role: - Actor + type: User - name: dest_device_id - type: Hostname role: - Victim + type: Hostname - name: cmd_line - type: processname role: - Others + type: processname product: - Splunk Behavioral Analytics required_fields: @@ -75,3 +81,16 @@ tags: risk_score: 90 risk_severity: high security_domain: endpoint +test: + name: Setting Credentials via PowerSploit modules - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + file_name: logAllPowerSploitModulesWithOldNames.log + source: WinEventLog:Security + description: Test illegal credential setting detections + file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml + name: Setting Credentials via PowerSploit modules + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml b/dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml new file mode 100644 index 0000000000..1d7a52b1dd --- /dev/null +++ b/dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml @@ -0,0 +1,102 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-07' +description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator + Tool) that delete backup files. This is typically used by ransomware to prevent + recovery. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: 71efbf52-4dbb-4c00-a520-306aa546cbb7 +known_false_positives: Administrators may modify the boot configuration. +name: WBAdmin Delete System Backups +product: +- Splunk Behavioral Analytics +references: +- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md +- https://thedfirreport.com/2020/10/08/ryuks-return/ +- https://attack.mitre.org/techniques/T1490/ +- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system + backups. +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), + "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), + "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", + null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", + null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where + cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" + AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, + "%systemstatebackup%") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name, "parent_process_name", parent_process_name, "process_path", process_path]) + | into write_ssa_detected_events();' +tags: + analytic_story: + - Ryuk Ransomware + - Ransomware + cis20: + - CIS 8 + confidence: 50 + context: + - Source:Endpoint + - stage:Defense Evasion + dataset: [] + impact: 30 + kill_chain_phases: + - Exploitation + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system + backups. + mitre_attack_id: + - T1490 + nist: + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 15 + risk_severity: medium + security_domain: endpoint +test: + name: WBAdmin Delete System Backups - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log + file_name: windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + description: Test detection of WBAdmin Delete System Backups + file: endpoint/ssa___wbadmin_delete_system_backups.yml + name: WBAdmin Delete System Backups + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml b/dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml new file mode 100644 index 0000000000..aaeeca58e6 --- /dev/null +++ b/dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml @@ -0,0 +1,97 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-06-15' +description: The wevtutil.exe application is the windows event log utility. This searches + for wevtutil.exe with parameters for clearing the application, security, setup, + powershell, sysmon, or system event logs. +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +id: 5438113c-cdd9-11eb-93b8-acde48001122 +known_false_positives: The wevtutil.exe application is a legitimate Windows event + log utility. Administrators may use it to manage Windows event logs. +name: WevtUtil Usage To Clear Logs +product: +- Splunk Behavioral Analytics +references: +- https://www.splunk.com/en_us/blog/security/detecting-clop-ransomware.html +risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear + event logs in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, + /(?i)security/)=true OR match_regex(cmd_line, /(?i)system/)=true OR match_regex(cmd_line, + /(?i)sysmon/)=true OR match_regex(cmd_line, /(?i)application/)=true OR match_regex(cmd_line, + /(?i)setup/)=true OR match_regex(cmd_line, /(?i)powershell/)=true) AND process_name="wevtutil.exe" + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Log Manipulation + - Ransomware + - Clop Ransomware + cis20: + - CIS 8 + - CIS 13 + confidence: 90 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log + impact: 70 + kill_chain_phases: + - Exploitation + message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear + event logs in host $dest_device_id$ + mitre_attack_id: + - T1070 + - T1070.001 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + risk_score: 63 + risk_severity: low + security_domain: endpoint +test: + name: WevtUtil Usage To Clear Logs Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log + file_name: clear_evt.log + source: WinEventLog:Security + description: Test for wevtutil clear logs command + file: endpoint/ssa___wevtutil_usage_to_clear_logs.yml + name: WevtUtil Usage To Clear Logs + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml b/dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml new file mode 100644 index 0000000000..72fb55c1ca --- /dev/null +++ b/dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml @@ -0,0 +1,93 @@ +author: Teoderick Contreras, Splunk +datamodel: +- Endpoint_Processes +date: '2021-06-15' +description: This search is to detect execution of wevtutil.exe to disable logs. This + technique was seen in several ransomware to disable the event logs to evade alerts + and detections in compromised host. +how_to_implement: You must be ingesting data that records process activity from your + hosts to populate the Endpoint data model in the Processes node. You must also be + ingesting logs with both the process name and command line from your endpoints. + The command-line arguments are mapped to the "process" field in the Endpoint data + model. +id: a4bdc944-cdd9-11eb-ac97-acde48001122 +known_false_positives: network operator may disable audit event logs for debugging + purposes. +name: Wevtutil Usage To Disable Logs +product: +- Splunk Behavioral Analytics +references: +- https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/ +risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable + event logs in host $dest_device_id$ +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, "%/e:false%") + AND process_name="wevtutil.exe" | eval start_time=timestamp, end_time=timestamp, + entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, + "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, + "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, + "process_path", process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Windows Log Manipulation + - Ransomware + cis20: + - CIS 8 + - CIS 13 + confidence: 90 + context: + - source:endpoint + - stage: Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log + impact: 70 + kill_chain_phases: + - Exploitation + message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable + event logs in host $dest_device_id$ + mitre_attack_id: + - T1070 + - T1070.001 + nist: + - PR.DS + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + risk_score: 63 + risk_severity: low + security_domain: endpoint +test: + name: Wevtutil Usage To Disable Logs Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log + file_name: disable_evt.log + source: WinEventLog:Security + description: Test for wevtutil disable logs command + file: endpoint/ssa___wevtutil_usage_to_disable_logs.yml + name: Wevtutil Usage To Disable Logs + pass_condition: '@count_gt(0)' +type: TTP +version: 2 diff --git a/dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml b/dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml new file mode 100644 index 0000000000..af6e699d71 --- /dev/null +++ b/dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml @@ -0,0 +1,115 @@ +author: Michael Haag, Splunk +datamodel: +- Endpoint_Processes +date: '2021-12-03' +description: 'The following analytic identifies the use of Windows Curl.exe uploading + a file to a remote destination. \ + + `-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. + \ + + `-d` or `--data` POST is the HTTP method that was invented to send data to a receiving + web application, and it is, for example, how most common HTML forms on the web work. + \ + + HTTP multipart formposts are done with `-F`, but this appears to not be compatible + with the Windows version of Curl. Will update if identified adversary tradecraft. + \ + + Adversaries may use one of the three methods based on the remote destination and + what they are attempting to upload (zip vs txt). During triage, review parallel + processes for further behavior. In addition, identify if the upload was successful + in network logs. If a file was uploaded, isolate the endpoint and review.' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint_Processess` datamodel. +id: cc8d046a-543b-11ec-b864-acde48001122 +known_false_positives: False positives may be limited to source control applications + and may be required to be filtered out. +name: Windows Curl Upload to Remote Destination +product: +- Splunk Behavioral Analytics +references: +- https://everything.curl.dev/usingcurl/uploads +- https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409 +- https://twitter.com/d1r4c/status/1279042657508081664?s=20 +risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote + destination. +search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, + "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), + "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + + | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="curl.exe" + AND (like (cmd_line, "%-T %") OR like (cmd_line, "%--upload-file %")OR like (cmd_line, + "%-d %") OR like (cmd_line, "%--data %") OR like (cmd_line, "%-F %")) + + | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, + "process_name", process_name, "parent_process_name", parent_process_name, "process_path", + process_path]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Ingress Tool Transfer + automated_detection_testing: passed + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log + impact: 80 + kill_chain_phases: + - Exfiltration + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote + destination. + mitre_attack_id: + - T1105 + observable: + - name: dest_user_id + role: + - Victim + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: parent_process_name + role: + - Parent Process + type: Parent Process + - name: process_name + role: + - Child Process + type: Process + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - dest_device_id + - process_name + - parent_process_name + - process_path + - dest_user_id + - process + - cmd_line + risk_score: 80 + risk_severity: high + security_domain: endpoint +test: + name: Windows Curl Upload to Remote Destination Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + file: endpoint/ssa___windows_curl_upload_to_remote_destination.yml + name: Windows Curl Upload to Remote Destination + pass_condition: '@count_gt(0)' +type: TTP +version: 1 diff --git a/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml b/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml deleted file mode 100644 index 9c28659f43..0000000000 --- a/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_s_option.yml +++ /dev/null @@ -1,92 +0,0 @@ -name: Credential Extraction indicative of FGDump and CacheDump with s option -id: 312582f2-5e91-42c1-a275-cd67f31373c8 -version: 2 -date: '2021-11-29' -author: Stanislav Miskovic, Splunk -type: TTP -datamodel: -- Endpoint_Processes -description: The following analytic identifies the use of CacheDump with the `-s` - parameter to dump cached credentials on the associated endpoint. Adversaries use - Cachedump as it is a publicly-available tool that extracts cached password hashes - from a system's registry. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND process_name != null AND parent_process_name != null - AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, - /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true - AND match_regex(cmd_line, /(?i)\-s/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: False positives will be limited as this analytic targets specific - credential dumping process names. Filter as needed. -references: -- https://attack.mitre.org/software/S0119/ -- https://en.kali.tools/all/?tool=182 -- http://foofus.net/goons/fizzgig/fgdump/ -- https://attack.mitre.org/software/S0120/ -tags: - analytic_story: - - Unusual Processes - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$. - mitre_attack_id: - - T1003 - - T1003.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: process_name - type: Process - role: - - Child Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 70 - risk_severity: high - security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml b/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml deleted file mode 100644 index b1f22d6bb8..0000000000 --- a/dist/ssa/deprecated/ssa___credential_extraction_fgdump_cachedump_v_option.yml +++ /dev/null @@ -1,85 +0,0 @@ -name: Credential Extraction indicative of FGDump and CacheDump with v option -id: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 -version: 2 -date: '2021-11-29' -author: Stanislav Miskovic, Splunk -type: TTP -datamodel: -- Endpoint_Processes -description: The following analytic identifies the use of CacheDump with the `-v` - parameter to dump cached credentials on the associated endpoint. Adversaries use - Cachedump as it is a publicly-available tool that extracts cached password hashes - from a system's registry. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, - /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true - AND match_regex(cmd_line, /(?i)\-v/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -known_false_positives: False positives will be limited as this analytic targets specific - credential dumping process names. Filter as needed. -references: [] -tags: - analytic_story: - - Unusual Processes - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ - mitre_attack_id: - - T1003 - - T1003.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: process_name - type: Process - role: - - Child Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 63 - risk_severity: high - security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml b/dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml deleted file mode 100644 index f7d42f0841..0000000000 --- a/dist/ssa/deprecated/ssa___credential_extraction_getaddbaccount_from_dump.yml +++ /dev/null @@ -1,77 +0,0 @@ -name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and - DSInternals -id: e4f126b5-e6bc-4a5c-b1a8-d07bc6c4a49f -version: 1 -date: '2020-10-18' -author: Stanislav Miskovic, Splunk -type: TTP -datamodel: -- Endpoint_Processes -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. PowerSploit - and DSInternals are common exploit APIs offering PowerShell modules for various - exploits of Windows and Active Directory environments. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, - /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\|]+/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: [] -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount - module. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: cmd_line - type: processname - role: - - Others - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 63 - risk_severity: high - security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml b/dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml deleted file mode 100644 index e18d3f48ad..0000000000 --- a/dist/ssa/deprecated/ssa___credential_extraction_lazagne_command_options.yml +++ /dev/null @@ -1,76 +0,0 @@ -name: Credential Extraction indicative of Lazagne command line options -id: 341975fa-4ad0-4f01-9acc-df4f69742db7 -version: 1 -date: '2020-10-18' -author: Stanislav Miskovic, Splunk -type: TTP -datamodel: -- Endpoint_Processes -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. LaZagne is - a tool that extracts various kinds of credentials from a local computer, including - account passwords, domain passwords, browser passwords, etc. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, - /(?i)all\s+\-oA\s+\-output/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: None identified. -references: [] -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Lazagne malware is extracting/decoding encoded credentials. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ - mitre_attack_id: - - T1003 - - T1555 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: cmd_line - type: processname - role: - - Others - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 63 - risk_severity: high - security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml b/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml deleted file mode 100644 index b5ad8dfcc2..0000000000 --- a/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_kernel_peek.yml +++ /dev/null @@ -1,86 +0,0 @@ -name: Credential Extraction native Microsoft debuggers peek into the kernel -id: c20bb8ec-e1b0-4640-b0ef-3a4c54f8c112 -version: 1 -date: '2020-10-18' -author: Stanislav Miskovic, Splunk -type: TTP -datamodel: -- Endpoint_Processes -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. Native Microsoft - debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential - material directly from memory and process dumps. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line != null AND parent_process_name != null AND process_name - != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, - /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true - AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: Although unlikely, using debuggers this way may be indicative - of developers analyzing crash dumps of their code. Note, even for developers this - is an unusual way of working on code - debuggers are mostly used to step through - code, not analyze its crash dumps. -references: -- https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29 -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: cmd_line - type: processname - role: - - Others - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 63 - risk_severity: medium - security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml b/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml deleted file mode 100644 index a8c42624e1..0000000000 --- a/dist/ssa/deprecated/ssa___credential_extraction_ms_debuggers_z_option.yml +++ /dev/null @@ -1,82 +0,0 @@ -name: Credential Extraction native Microsoft debuggers via z command line option -id: adc51a77-90c9-4358-b43c-f10dd1a27d05 -version: 1 -date: '2020-10-18' -author: Stanislav Miskovic, Splunk -type: TTP -datamodel: -- Endpoint_Processes -description: Credential extraction is often an illegal recovery of credential material - from secured authentication resources and repositories. This process may also involve - decryption or other transformations of the stored credential material. Native Microsoft - debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential - material directly from memory and process dumps. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line != null AND process_name != null AND ( match_regex(process_name, - /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, - /(?i)\-z\s+/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -known_false_positives: Although unlikely, using debuggers this way may be indicative - of developers analyzing crash dumps of their code. Note, even for developers this - is an unusual way of working on code - debuggers are mostly used to step through - code, not analyze its crash dumps. -references: [] -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: cmd_line - type: processname - role: - - Others - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 63 - risk_severity: medium - security_domain: endpoint diff --git a/dist/ssa/deprecated/ssa___detect_pass_hash.yml b/dist/ssa/deprecated/ssa___detect_pass_hash.yml deleted file mode 100644 index cd076b5e12..0000000000 --- a/dist/ssa/deprecated/ssa___detect_pass_hash.yml +++ /dev/null @@ -1,83 +0,0 @@ -name: Detect Pass the Hash -id: 7cd8b9fa-6b0c-424f-92a6-9c5287a72f5f -version: 1 -date: '2020-10-21' -author: Xiao Lin, Splunk -type: TTP -datamodel: -- Authentication -description: This search looks for specific authentication events from the Windows - Security Event logs to detect potential attempts using Pass-the-Hash technique. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) - | eval signature_id=map_get(input_event, "signature_id"), authentication_type=map_get(input_event, - "authentication_type"), authentication_method=map_get(input_event, "authentication_method"), - origin_device_domain=map_get(input_event, "origin_device_domain"), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - - | where (authentication_type="3" AND authentication_method="NtLmSsp") OR (authentication_type="9" - AND authentication_method="seclogo") - - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "authentication_type", authentication_type, - "authentication_method", authentication_method]) | into write_ssa_detected_events();' -how_to_implement: The test data is converted from Windows Security Event logs generated - from Attach Range simulation and used in SPL search and extended to SPL2 -known_false_positives: Legitimate logon activity by authorized NTLM systems may be - detected by this search. Please investigate as appropriate. -references: -- Initial ESCU implementation by Bhavin Patel and Patrick Bareiss -tags: - analytic_story: - - Lateral Movement - cis20: - - CIS 3 - - CIS 5 - - CIS 16 - confidence: 20 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Potential use of the pass the hash/token attacks that spoof authentication. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1550 - - T1550.002 - nist: - - PR.PT - - PR.AT - - PR.AC - - PR.IP - observable: - - name: dest_user_id - type: User - role: - - Actor - - name: dest_device_id - type: Hostname - role: - - Victim - - name: cmd_line - type: processname - role: - - Others - product: - - Splunk Behavioral Analytics - required_fields: - - signature_id - - authentication_type - - _time - - authentication_method - - origin_device_domain - - dest_user_id - - dest_device_id - risk_score: 16 - risk_severity: low - security_domain: endpoint diff --git a/dist/ssa/srs/ssa___detect_kerberoasting.yml b/dist/ssa/srs/ssa___detect_kerberoasting.yml new file mode 100644 index 0000000000..0d07185006 --- /dev/null +++ b/dist/ssa/srs/ssa___detect_kerberoasting.yml @@ -0,0 +1,94 @@ +author: Xiao Lin, Splunk +datamodel: +- Certificates +date: '2020-10-21' +description: This search detects a potential kerberoasting attack via service principal + name requests +how_to_implement: The test data is converted from Windows Security Event logs generated + from Attach Range simulation and used in SPL search and extended to SPL2 +id: dabdd6d7-3e10-42be-8711-4e124f7a3850 +known_false_positives: Older systems that support kerberos RC4 by default NetApp may + generate false positives +name: Detect Kerberoasting +product: +- Splunk Behavioral Analytics +references: +- Initial ESCU implementation by Jose Hernandez and Patrick Bareiss +risk_message: Kerberoasting malware is potentially applying stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via command + $cmd_line$ +search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), + EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, + "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), + ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, + "service_id"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), + event_id=ucast(map_get(input_event, "event_id"), "string", null) | where EventCode="4769" + AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" | first_time_event + input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] + | where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID + | eval start_time=_time, end_time=_time | eval body=create_map(["event_id", event_id, + "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, + "TicketEncryptionType", TicketEncryptionType]), entities = mvappend(ucast(map_get(input_event, + "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), + "string", null)) | select start_time, end_time, entities, body | into write_ssa_detected_events();' +tags: + analytic_story: + - Credential Dumping + cis20: + - CIS 8 + - CIS 16 + confidence: 20 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + impact: 70 + kill_chain_phases: + - Actions on Objectives + message: Kerberoasting malware is potentially applying stolen credentials. Operation + is performed at the device $dest_device_id$, by the account $dest_user_id$ via + command $cmd_line$ + mitre_attack_id: + - T1558.003 + - T1558 + nist: + - DE.CM + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Victim + type: Hostname + - name: cmd_line + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - service_name + - _time + - event_code + - ticket_encryption_type + - service_id + - ticket_options + risk_score: 14 + risk_severity: medium + security_domain: endpoint +test: + name: Detect Kerberoasting - SSA Unit test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test detection of kerberoasting + file: endpoint/ssa___detect_kerberoasting.yml + name: Detect kerberoasting + pass_condition: '@count_eq(0)' +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml b/dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml new file mode 100644 index 0000000000..8a239045f5 --- /dev/null +++ b/dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml @@ -0,0 +1,64 @@ +author: Patrick Bareiss, Splunk +datamodel: +- Endpoint_Filesystem +date: '2021-12-07' +description: This detection detects a high amount of office file copied. This can + be an indicator for a malicious insider. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Filesytem` node. +id: 3c6594a9-8df6-45a1-9357-d73b62083c63 +known_false_positives: user may copy a lot of office fies from one folder to another +name: Excessive Number of Office Files Copied +product: +- Splunk Behavioral Analytics +references: [] +risk_message: High number of files copied +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", + null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, + "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) + | where "Endpoint_Filesystem" IN(_datamodels) | where action="created" | where like(file_name, + "%.doc%") OR like(file_name, "%.xls%") OR like(file_name, "%.ppt%") | stats count(file_name) + AS count BY dest_user_id, dest_device_id, span(timestamp, 10m) | where count > 20 + | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, + dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' +tags: + analytic_story: [] + confidence: 80 + context: + - Source:Endpoint + - Stage:Exfitration + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: High number of files copied + mitre_attack_id: + - T1048.003 + product: + - Splunk Behavioral Analytics + required_fields: + - action + - process + - file_name + - file_path + risk_score: 72 + risk_severity: low + security_domain: endpoint +test: + name: Excessive Number of Office Files Copied Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log + file_name: sysmon.log + source: xmlwineventlog + description: Test for Excessive Number of Office Files Copied + file: endpoint/ssa___excessive_number_of_office_files_copied.yml + name: Excessive Number of Office Files Copied + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml b/dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml new file mode 100644 index 0000000000..5bed7361d2 --- /dev/null +++ b/dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml @@ -0,0 +1,89 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: This search looks for command-line arguments that use a `/c` parameter + to execute a command that has not previously been seen. This is an implementation + on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following + analytic identifies first time seen command-line arguments on a single endpoint. + The analytic looks for arguments instantiated by `cmd.exe /c` and the associated + command-line. Adversaries automate or spawn multiple processes using this method, + this analytic may assist with identifying the first time it's been found on this + endpoint.' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +id: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 +known_false_positives: Legitimate programs use command-line arguments to execute. + Verify the command-line arguments to check what command/program is being executed. + Filtering will be needed. +name: First time seen command line argument +product: +- Splunk Behavioral Analytics +references: [] +risk_message: A process $process_name$ ha been identified in the environment with + a command-line $cmd_line$ not previously seen before on host $dest_device_id$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), + "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", + null), process_name=ucast(map_get(input_event, "process_name"), "string", null), + cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), + cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, + "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, + "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" + */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, "\\PATH"), + /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, + /\d+/, "N"), event_id=ucast(map_get(input_event, "event_id"), "string", null) | + where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* + \/[cC] .*/)=true | select process_name, cmd_line, cmd_line_norm, timestamp, dest_device_id, + dest_user_id | first_time_event input_columns=["cmd_line_norm"] | where first_time_cmd_line_norm + | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, + dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", + process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 3 + - CIS 8 + confidence: 60 + context: + - source:endpoint + - stage: Defense Evasion + impact: 50 + kill_chain_phases: + - Command and Control + - Actions on Objectives + message: A process $process_name$ ha been identified in the environment with a command-line + $cmd_line$ not previously seen before on host $dest_device_id$ + mitre_attack_id: + - T1059 + - T1202 + nist: + - PR.PT + - DE.CM + - PR.IP + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _time + - dest_device_id + - dest_user_id + - process + - cmd_line + risk_score: 30 + risk_severity: medium + security_domain: endpoint +type: Anomaly +version: 4 diff --git a/dist/ssa/srs/ssa___high_file_deletion_frequency.yml b/dist/ssa/srs/ssa___high_file_deletion_frequency.yml new file mode 100644 index 0000000000..d8d355b0a6 --- /dev/null +++ b/dist/ssa/srs/ssa___high_file_deletion_frequency.yml @@ -0,0 +1,85 @@ +author: Patrick Bareiss, Splunk +datamodel: +- Endpoint_Filesystem +date: '2021-12-07' +description: This detection detects a high amount of file deletions in a short time + for specific file types. This can be an indicator for a malicious insider. +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Filesytem` node. +id: b6200efd-13bd-4336-920a-057b25bbcfaf +known_false_positives: user may delete bunch of pictures or files in a folder. +name: High File Deletion Frequency +product: +- Splunk Behavioral Analytics +references: +- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html +- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html +risk_message: High frequency file deletion activity detected on host $Computer$ +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", + null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, + "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) + | where "Endpoint_Filesystem" IN(_datamodels) | where action="deleted" | where like(file_name, + "%.cmd") OR like(file_name, "%.ini") OR like(file_name, "%.gif") OR like(file_name, + "%.jpg") OR like(file_name, "%.jpeg") OR like(file_name, "%.db") OR like(file_name, + "%.doc%") OR like(file_name, "%.ps1") OR like(file_name, "%.xls%") OR like(file_name, + "%.ppt%") OR like(file_name, "%.bmp") OR like(file_name, "%.zip") OR like(file_name, + "%.rar") OR like(file_name, "%.7z") OR like(file_name, "%.chm") OR like(file_name, + "%.png") OR like(file_name, "%.log") OR like(file_name, "%.vbs") OR like(file_name, + "%.js") | stats count(file_name) AS count BY dest_user_id, dest_device_id, span(timestamp, + 10m) | where count > 20 | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, + dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Clop Ransomware + confidence: 80 + context: + - Source:Endpoint + - Stage:Execution + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log + impact: 90 + kill_chain_phases: + - Exploitation + message: High frequency file deletion activity detected on host $Computer$ + mitre_attack_id: + - T1485 + observable: + - name: user + role: + - Victim + type: User + - name: Computer + role: + - Victim + type: Endpoint + - name: deleted_files + role: + - Target + type: File Name + product: + - Splunk Behavioral Analytics + required_fields: + - action + - process + - file_name + - file_path + risk_score: 72 + risk_severity: low + security_domain: endpoint +test: + name: High File Deletion Frequency Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log + file_name: sysmon.log + source: xmlwineventlog + description: Test for High File Deletion Frequency + file: endpoint/ssa___high_file_deletion_frequency.yml + name: High File Deletion Frequency + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml b/dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml new file mode 100644 index 0000000000..5995bc4c02 --- /dev/null +++ b/dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml @@ -0,0 +1,95 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2020-08-25' +description: Attacker activity may compromise executing several LOLBAS applications + in conjunction to accomplish their objectives. We are looking for more than usual + LOLBAS applications over a window of time, by building profiles per machine. +how_to_implement: Collect endpoint data such as sysmon or 4688 events. +id: 59c0dd70-169c-4900-9a1f-bfcf13302f93 +known_false_positives: 'Some administrative tasks may involve multiple use of LOLBAS + applications in a short period of time. This might trigger false positives at the + beginning when it hasn''t collected yet enough data to construct the baseline. + + ' +name: More than usual number of LOLBAS applications in short time period +product: +- Splunk Behavioral Analytics +references: +- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries +risk_message: A system process $process_name$ with commandline $cmd_line$ spawn iin + short period of time in host $dest_device_id$ +search: ' | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, + "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, + "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | where process_name=="regsvcs.exe" OR process_name=="ftp.exe" + OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" + OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" + OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" + OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" + OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" + OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" + OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" + OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" + OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" + OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" + OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" + OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" + OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" + OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" + OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" + OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" + OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" + OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" + OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" + OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR + process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" + OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" + OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" + OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" + OR process_name=="msconfig.exe" | stats count(process_name) as lolbas_counter by + device,span(timestamp, 300s) | eval lolbas_counter=lolbas_counter*1.0 | rename window_end + as timestamp | adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" + window=2419200000L | where label AND quantile>0.99 | eval start_time = window_start, + end_time = timestamp, entities = mvappend(device), body=create_map(["lolbas_counter", + lolbas_counter, "quantile", quantile, "device", device]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 8 + confidence: 50 + context: + - source:endpoint + - stage: Defense Evasion + impact: 50 + kill_chain_phases: + - Exploitation + message: A system process $process_name$ with commandline $cmd_line$ spawn iin short + period of time in host $dest_device_id$ + mitre_attack_id: + - T1059 + - T1053 + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: process_name + role: + - Others + type: processname + product: + - Splunk Behavioral Analytics + required_fields: + - dest_device_id + - _time + - process_name + risk_score: 25 + risk_severity: medium + security_domain: endpoint +type: Anomaly +version: 2 diff --git a/dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml b/dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml new file mode 100644 index 0000000000..c1f2707376 --- /dev/null +++ b/dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml @@ -0,0 +1,62 @@ +author: Xiao Lin, Splunk +datamodel: [] +date: '2020-08-25' +description: Malicious mails can conduct phishing that induces readers to open attachment, + click links or trigger third party service. This detect uses Natural Language Processing + (NLP) approach to analyze an email message's content (Sender, Subject and Body) + and judge whether it is a phishing email. The detection adopts a deep learning (neural + network) model that employs character level embeddings plus LSTM layers to perform + classification. The model is pre-trained and then published as ONNX format. Current + sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json + User are expected to re-train the model by combining with their own training data + for better accuracy using the provided model file (SMLE notebook). DSP pipeline + then processes the email message and passes it as an event to Apply ML Models function, + which returns the probability of a phishing email. Current implementation assumes + the email is fed to DSP in JSON format contains at least email's sender, subject + and its message body, including reply content, if any. +how_to_implement: Events are fed to DSP contains at least email's sender, subject + and its message body. +id: 4b237388-dfa1-41a6-91d4-4de2d598376f +known_false_positives: Because of imbalance of anomaly data in training, the model + will less likely report false positive. Instead, the model is more prone to false + negative. Current best recall score is ~85% +name: Phishing Email Detection by Machine Learning Method - SSA +product: +- Splunk Behavioral Analytics +references: [] +search: '| from read_ssa_enriched_events() | eval eventLine=concat(ucast(map_get(input_event, + "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " + "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), + _time=map_get(input_event, "_time") | where eventLine IS NOT NULL | eval mapC={" + ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, + ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, + "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, + ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, + "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, + "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, + "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, + "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": + 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": + 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": + 119, "x": 120, "y": 121, "z": 122, "{": 123, "|": 124, "}": 125, "~": 126}, ml_in + = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, + 1)), "float") ) | apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" + path="s3://smle-experiments/models/phishing_email" | eval probability = mvindex(ml_out, + 0) | where probability > 0.5 | eval start_time=_time, end_time=_time, entities="TBD", + body="TBD" | select probability, body, entities, start_time, end_time | into write_ssa_detected_events();' +tags: + cis20: + - CIS 8 + kill_chain_phases: + - Actions on Objectives + mitre_attack_id: + - T1566 + nist: + - PR.PT + - DE.CM + product: + - Splunk Behavioral Analytics + risk_severity: low + security_domain: mail server +type: Anomaly +version: 1 diff --git a/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml b/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml new file mode 100644 index 0000000000..e1415eadc5 --- /dev/null +++ b/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml @@ -0,0 +1,102 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Authentication +date: '2021-11-30' +description: This detection identifies potential Pass the Token or Pass the Hash credential + stealing. We detect the main side effect of these attacks, which is a transition + from the dominant Kerberos logins to rare NTLM logins for a given user, as reported + by a detination device. +how_to_implement: You must be ingesting Windows Security logs from endpoint devices, + i.e., destinations of interest. Please make sure that event ID 4624 is being logged. +id: 82e76b80-5cdb-4899-9b43-85dbe777b36d +known_false_positives: Environments in which NTLM is used extremely rarely and for + benign purposes (such as a rare use of SMB shares). +name: Potential Pass the Token or Hash Observed at the Destination Device +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1550/002/ +- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ +risk_message: Potential lateral movement and credential stealing via Pass the Token + or Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the destination device $dest_device_id$ +search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", + null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), + dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), + signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), + authentication_method= lower(ucast(map_get(input_event, "authentication_method"), + "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) + + | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") + AND dest_user_id != null AND dest_device_id != null + + | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method + == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) + + | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as + startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as + endNTLMTime by dest_user_id, dest_user, dest_device_id, span(timestamp, 86400s) + + | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - + startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND + (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) + + | eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, + "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["event_id", + event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", + startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", + endNTLMTime]) + + | into write_ssa_detected_events();' +tags: + analytic_story: + - Active Directory Lateral Movement + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 90 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Stage:Lateral Movement + impact: 80 + kill_chain_phases: + - Lateral Movement + message: Potential lateral movement and credential stealing via Pass the Token or + Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the destination device $dest_device_id$ + mitre_attack_id: + - T1550 + - T1550.002 + nist: + - PR.PT + - PR.AT + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: dest_device_id + role: + - Other + type: Hostname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - signature_id + - dest_user + - dest_user_id + - dest_device_id + - authentication_method + risk_score: 72 + risk_severity: low + security_domain: endpoint +type: TTP +version: 3 diff --git a/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml b/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml new file mode 100644 index 0000000000..74810e4d36 --- /dev/null +++ b/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml @@ -0,0 +1,103 @@ +author: Stanislav Miskovic, Splunk +datamodel: +- Authentication +date: '2021-11-05' +description: This detection identifies potential Pass the Token or Pass the Hash credential + stealing. We detect the main side effect of these attacks, which is a transition + from the dominant Kerberos logins to rare NTLM logins for a given user, as reported + by an event-collecting device (i.e., a specific domain controller or an endpoint + destination). +how_to_implement: You must be ingesting Windows Security logs from devices of interest + - at least from domain controllers. Please make sure that event ID 4624 is being + logged. +id: 1058ba3e-a698-49bc-a1e5-7cedece4ea87 +known_false_positives: Environments in which NTLM is used extremely rarely and for + benign purposes (such as a rare use of SMB shares). +name: Potential Pass the Token or Hash Observed by an Event Collecting Device +product: +- Splunk Behavioral Analytics +references: +- https://attack.mitre.org/techniques/T1550/002/ +- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ +risk_message: Potential lateral movement and credential stealing via Pass the Token + or Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the logging device $origin_device_id$ +search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) + + | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), + dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), + "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", + null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", + null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", + null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), + "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") + AND dest_user_id != null AND origin_device_id != null + + | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method + == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) + + | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as + startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as + endNTLMTime by dest_user_id, dest_user, origin_device_id, span(timestamp, 86400s) + + | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - + startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND + (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) + + | eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, + origin_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, + "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", + endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) + + | into write_ssa_detected_events();' +tags: + analytic_story: + - Active Directory Lateral Movement + asset_type: Windows + cis20: + - CIS 16 + - CIS 20 + confidence: 80 + context: + - Source:AD + - Source:Endpoint + - Stage:Credential Access + - Stage:Lateral Movement + impact: 80 + kill_chain_phases: + - Lateral Movement + message: Potential lateral movement and credential stealing via Pass the Token or + Pass the Hash techniques. Operation is performed via credentials of the account + $dest_user_id$ and observed by the logging device $origin_device_id$ + mitre_attack_id: + - T1550 + - T1550.002 + nist: + - PR.PT + - PR.AT + - PR.AC + - PR.IP + observable: + - name: dest_user_id + role: + - Actor + type: User + - name: origin_device_id + role: + - Other + type: Hostname + product: + - Splunk Behavioral Analytics + required_fields: + - _time + - signature_id + - dest_user + - dest_user_id + - origin_device_id + - authentication_method + risk_score: 64 + risk_severity: low + security_domain: endpoint +type: TTP +version: 2 diff --git a/dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml b/dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml new file mode 100644 index 0000000000..4f0ce19970 --- /dev/null +++ b/dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml @@ -0,0 +1,88 @@ +author: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2021-11-30' +description: An attacker may use LOLBAS tools spawned from vulnerable applications + not typically used by system administrators. This analytic leverages the Splunk + Streaming ML DSP plugin to find rare parent/child relationships. The list of application + has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries +how_to_implement: Collect endpoint data such as sysmon or 4688 events. +id: cf090c78-bcc6-11eb-8529-0242ac130003 +known_false_positives: Some custom tools used by administrators could be used rarely + to launch remotely applications. This might trigger false positives at the beginning + when it has not collected yet enough data to construct the baseline. +name: Rare Parent-Child Process Relationship +product: +- Splunk Behavioral Analytics +references: +- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries +search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval parent_process=lower(ucast(map_get(input_event, + "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, + "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", + null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, + "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), + "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) + | where parent_process_name!=null | select parent_process_name, process_name, cmd_line, + timestamp, dest_device_id, dest_user_id | conditional_anomaly conditional="parent_process_name" + target="process_name" | where (process_name="powershell.exe" OR process_name="regsvcs.exe" + OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" + OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" + OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" + OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" + OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" + OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" + OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" + OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" + OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" + OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" + OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" + OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" + OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" + OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" + OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" + OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" + OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" + OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" + OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" + OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" + OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR + process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" + OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" + OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" + OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") + | eval input = (-1)*log(output) | adaptive_threshold algorithm="gaussian" threshold=0.001 + window=604800000L | where label AND input > mean | eval start_time = timestamp, + end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = + create_map(["process_name", process_name, "parent_process_name", parent_process_name, + "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", + cmd_line]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 8 + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1203 + - T1059 + - T1053 + - T1072 + nist: + - PR.PT + - DE.CM + product: + - Splunk Behavioral Analytics + required_fields: + - process + - process_name + - parent_process_name + - _time + - dest_device_id + - dest_user_id + - cmd_line + risk_severity: low + security_domain: endpoint +type: Anomaly +version: 2 diff --git a/dist/ssa/srs/ssa___unusually_long_command_line.yml b/dist/ssa/srs/ssa___unusually_long_command_line.yml new file mode 100644 index 0000000000..7431805fa7 --- /dev/null +++ b/dist/ssa/srs/ssa___unusually_long_command_line.yml @@ -0,0 +1,87 @@ +author: Ignacio Bermudez Corrales, Splunk +datamodel: +- Endpoint_Processes +date: '2020-10-06' +description: Command lines that are extremely long may be indicative of malicious + activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin + to help identify command lines with lengths that are unusual for a given user. This + detection is inspired on Unusually Long Command Line authored by Rico Valdez. +how_to_implement: You must be ingesting sysmon endpoint data that monitors command + lines. +id: 58f43aba-1775-445e-b19c-be2b87d83ae3 +known_false_positives: This detection may flag suspiciously long command lines when + there is not sufficient evidence (samples) for a given process that this detection + is tracking; or when there is high variability in the length of the command line + for the tracked process. Also, some legitimate applications may use long command + lines. Such is the case of Ansible, that encodes Powershell scripts using long base64. + Attackers may use this technique to obfuscate their payloads. +name: Unusually Long Command Line +product: +- Splunk Behavioral Analytics +references: [] +risk_message: A process $process_name$ with a long commandline $cmd_line$ executed + in host $dest_device_id$ +search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, + "_time"), "string", null)) | eval cmd_line=ucast(map_get(input_event, "process"), + "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", + null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), + process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, + "event_id"), "string", null) | where cmd_line!=null and dest_user_id!=null | eval + cmd_line_norm=replace(cast(cmd_line, "string"), /\s(--?\w+)|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, + /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, + ""))) | select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, + input | adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 + | where label AND quantile>0.99 | first_time_event input_columns=["dest_device_id", + "cmd_line"] | where first_time_dest_device_id_cmd_line | eval start_time = timestamp, + end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", + event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' +tags: + analytic_story: + - Unusual Processes + cis20: + - CIS 8 + confidence: 40 + context: + - source:endpoint + - stage: Defense Evasion + impact: 30 + kill_chain_phases: + - Actions on Objectives + message: A process $process_name$ with a long commandline $cmd_line$ executed in + host $dest_device_id$ + nist: + - PR.PT + - DE.CM + observable: + - name: dest_device_id + role: + - Victim + type: Hostname + - name: dest_user_id + role: + - Victim + type: user + product: + - Splunk Behavioral Analytics + required_fields: + - process_name + - _time + - dest_device_id + - dest_user_id + - process + risk_score: 12 + risk_severity: medium + security_domain: endpoint +test: + name: Unusually Long Command Line - SSA Unit Test + tests: + - attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/unusally_cmd_line/windows-security.log + file_name: windows-security.log + source: WinEventLog:Security + description: Test unusually long command lines + file: endpoint/ssa___unusually_long_command_line.yml + name: Unusually Long Command Line + pass_condition: '@count_gt(0)' +type: Anomaly +version: 1 diff --git a/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml b/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml index 586a4f6173..af6e699d71 100644 --- a/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml +++ b/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml @@ -107,7 +107,7 @@ test: - attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log file_name: windows-security.log - source: WinEventLog:security + source: WinEventLog:Security file: endpoint/ssa___windows_curl_upload_to_remote_destination.yml name: Windows Curl Upload to Remote Destination pass_condition: '@count_gt(0)' From 6edaa90519b6e2d0473db06b7ce093fbd9fe97ca Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 10 Jan 2022 15:12:30 -0500 Subject: [PATCH 4/9] updated generate to match javiers feedback --- bin/generate.py | 9 +- ...ssa___anomalous_usage_of_archive_tools.yml | 96 ------------- ...tolen_credentials_via_mimikatz_modules.yml | 126 ------------------ ...en_credentials_via_powersploit_modules.yml | 121 ----------------- ...ntial_strength_via_dsinternals_modules.yml | 93 ------------- .../ssa___attempt_to_delete_services.yml | 106 --------------- .../ssa___attempt_to_disable_services.yml | 105 --------------- ..._bcdedit_failure_recovery_modification.yml | 99 -------------- ...nternals_credential_conversion_modules.yml | 104 --------------- ...dicative_of_use_of_dsinternals_modules.yml | 106 --------------- ..._indicative_of_use_of_mimikatz_modules.yml | 90 ------------- ...dicative_of_use_of_powersploit_modules.yml | 91 ------------- dist/ssa/complex/ssa___delete_a_net_user.yml | 109 --------------- ...___deny_permission_using_cacls_utility.yml | 92 ------------- ...detect_dump_lsass_memory_using_comsvcs.yml | 87 ------------ ...ohibited_applications_spawning_cmd_exe.yml | 103 -------------- ...ssa___detect_rclone_command-line_usage.yml | 97 -------------- .../ssa___disable_net_user_account.yml | 104 --------------- ...___dns_exfiltration_using_nslookup_app.yml | 104 --------------- .../ssa/complex/ssa___fsutil_zeroing_file.yml | 97 -------------- ...__grant_permission_using_cacls_utility.yml | 92 ------------- ...o_user_content_via_powersploit_modules.yml | 92 ------------- ...count_creation_via_powersploit_modules.yml | 93 ------------- ..._deletion_of_logs_via_mimikatz_modules.yml | 83 ------------ ...ng_of_accounts_via_dsinternals_modules.yml | 85 ------------ ...s_and_policies_via_dsinternals_modules.yml | 89 ------------- ...ctory_elements_via_powersploit_modules.yml | 90 ------------- ...nd_persistence_via_powersploit_modules.yml | 104 --------------- ...ivilege_elevation_via_mimikatz_modules.yml | 97 -------------- ...d_process_control_via_mimikatz_modules.yml | 100 -------------- ...rocess_control_via_powersploit_modules.yml | 110 --------------- ...fy_acls_permission_of_files_or_folders.yml | 96 ------------- ...ction_by_machine_learning_method_-_ssa.yml | 62 --------- ...en_credentials_via_powersploit_modules.yml | 96 ------------- ...counts_and_groups_via_mimikatz_modules.yml | 85 ------------ ...s_and_policies_via_powersploit_modules.yml | 109 --------------- ...infrastructure_via_powersploit_modules.yml | 98 -------------- ...rs_and_domains_via_powersploit_modules.yml | 90 ------------- ...cess_to_computers_via_mimikatz_modules.yml | 81 ----------- ...ystem_elements_via_powersploit_modules.yml | 98 -------------- ...sses_and_services_via_mimikatz_modules.yml | 80 ----------- ..._shared_resources_via_mimikatz_modules.yml | 85 ------------ ...ared_resources_via_powersploit_modules.yml | 90 ------------- ..._opportunities_via_powersploit_modules.yml | 101 -------------- ...f_connectivity_via_powersploit_modules.yml | 90 ------------- ...ores_and_services_via_mimikatz_modules.yml | 91 ------------- ...efensive_tools_via_powersploit_modules.yml | 83 ------------ ..._opportunities_via_powersploit_modules.yml | 82 ------------ ...ing_opportunities_via_mimikatz_modules.yml | 90 ------------- .../ssa___resize_shadowstorage_volume.yml | 105 --------------- .../ssa___sdelete_application_execution.yml | 110 --------------- ...ng_credentials_via_dsinternals_modules.yml | 106 --------------- ...tting_credentials_via_mimikatz_modules.yml | 96 ------------- ...ng_credentials_via_powersploit_modules.yml | 96 ------------- .../ssa___wbadmin_delete_system_backups.yml | 102 -------------- .../ssa___wevtutil_usage_to_clear_logs.yml | 97 -------------- .../ssa___wevtutil_usage_to_disable_logs.yml | 93 ------------- ...dows_curl_upload_to_remote_destination.yml | 115 ---------------- dist/ssa/srs/ssa___detect_kerberoasting.yml | 94 ------------- ...xcessive_number_of_office_files_copied.yml | 64 --------- ..._first_time_seen_command_line_argument.yml | 89 ------------- .../ssa___high_file_deletion_frequency.yml | 85 ------------ ...lbas_applications_in_short_time_period.yml | 95 ------------- ...ash_observed_at_the_destination_device.yml | 102 -------------- ...observed_by_an_event_collecting_device.yml | 103 -------------- ...rare_parent-child_process_relationship.yml | 88 ------------ .../srs/ssa___unusually_long_command_line.yml | 87 ------------ 67 files changed, 6 insertions(+), 6302 deletions(-) delete mode 100644 dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml delete mode 100644 dist/ssa/complex/ssa___applying_stolen_credentials_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___applying_stolen_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml delete mode 100644 dist/ssa/complex/ssa___attempt_to_delete_services.yml delete mode 100644 dist/ssa/complex/ssa___attempt_to_disable_services.yml delete mode 100644 dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml delete mode 100644 dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml delete mode 100644 dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml delete mode 100644 dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___delete_a_net_user.yml delete mode 100644 dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml delete mode 100644 dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml delete mode 100644 dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml delete mode 100644 dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml delete mode 100644 dist/ssa/complex/ssa___disable_net_user_account.yml delete mode 100644 dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml delete mode 100644 dist/ssa/complex/ssa___fsutil_zeroing_file.yml delete mode 100644 dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml delete mode 100644 dist/ssa/complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_account_creation_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___illegal_service_and_process_control_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml delete mode 100644 dist/ssa/complex/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml delete mode 100644 dist/ssa/complex/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___resize_shadowstorage_volume.yml delete mode 100644 dist/ssa/complex/ssa___sdelete_application_execution.yml delete mode 100644 dist/ssa/complex/ssa___setting_credentials_via_dsinternals_modules.yml delete mode 100644 dist/ssa/complex/ssa___setting_credentials_via_mimikatz_modules.yml delete mode 100644 dist/ssa/complex/ssa___setting_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml delete mode 100644 dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml delete mode 100644 dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml delete mode 100644 dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml delete mode 100644 dist/ssa/srs/ssa___detect_kerberoasting.yml delete mode 100644 dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml delete mode 100644 dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml delete mode 100644 dist/ssa/srs/ssa___high_file_deletion_frequency.yml delete mode 100644 dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml delete mode 100644 dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml delete mode 100644 dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml delete mode 100644 dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml delete mode 100644 dist/ssa/srs/ssa___unusually_long_command_line.yml diff --git a/bin/generate.py b/bin/generate.py index 9bca712718..84b03d31a9 100644 --- a/bin/generate.py +++ b/bin/generate.py @@ -105,17 +105,20 @@ def generate_ssa_yaml(detections, TEMPLATE_PATH, OUTPUT_PATH): yaml.Dumper.ignore_aliases = lambda *args : True # wiping old detections for SSA - shutil.rmtree(OUTPUT_PATH + '/srs/*', ignore_errors=True) - shutil.rmtree(OUTPUT_PATH + '/complex/*', ignore_errors=True) + shutil.rmtree(OUTPUT_PATH + '/srs/', ignore_errors=True) + shutil.rmtree(OUTPUT_PATH + '/complex/', ignore_errors=True) + os.makedirs(OUTPUT_PATH + '/complex/') + os.makedirs(OUTPUT_PATH + '/srs/') for d in detections: # check if the search contains "stats", "first_time_event", or "adaptive_threshold" which would make it a complex pipeline pattern = re.compile('stats|first_time_event|adaptive_threshold') if re.findall("stats|first_time_event|adaptive_threshold", d['search']): + # it is a complex pipeline manifest_file = OUTPUT_PATH + '/complex/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' - print(d['name']) else: + # it is a simple pipeline can be placed on SRS (Simple Rule Service) manifest_file = OUTPUT_PATH + '/srs/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' # remove unused fields diff --git a/dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml b/dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml deleted file mode 100644 index a0716cc96c..0000000000 --- a/dist/ssa/complex/ssa___anomalous_usage_of_archive_tools.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Patrick Bareiss, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-22' -description: The following detection identifies the usage of archive tools from the - command line. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. -id: 63614a58-10e2-4c6c-ae81-ea1113681439 -known_false_positives: False positives can be ligitmate usage of archive tools from - the command line. -name: Anomalous usage of Archive Tools -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1560/001/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading - of 7zip. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), - "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", - null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), - parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), parent_process=ucast(map_get(input_event, "parent_process"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where process_name - IS NOT NULL AND parent_process_name IS NOT NULL | where like(process_name, "7z%") - OR process_name="WinRAR.exe" OR like(process_name, "winzip%") | where like(parent_process_name, - "%cmd.exe") OR like(parent_process_name, "%powershell.exe") | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "process_name", process_name, "parent_process_name", - parent_process_name, "process_path", process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Cobalt Strike - - NOBELIUM Group - confidence: 60 - context: - - Source:Endpoint - - Stage:Collection - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log - impact: 70 - kill_chain_phases: - - Actions on Objective - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest$ by user $user$. This behavior is indicative of suspicious loading - of 7zip. - mitre_attack_id: - - T1560.001 - - T1560 - observable: - - name: user - role: - - Victim - type: User - - name: dest - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - Processes.process_name - - Processes.process - - Processes.dest - - Processes.user - - Processes.parent_process_name - - Processes.parent_process - risk_score: 42 - risk_severity: medium - security_domain: endpoint -test: - name: Anomalous usage of Archive Tools Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_tools/windows-security.log - file_name: security.log - source: WinEventLog:Security - description: Test for Anomalous usage of Archive Tools - file: endpoint/ssa___anomalous_usage_of_archive_tools.yml - name: Anomalous usage of Archive Tools - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/complex/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___applying_stolen_credentials_via_mimikatz_modules.yml deleted file mode 100644 index c2d7b5f6be..0000000000 --- a/dist/ssa/complex/ssa___applying_stolen_credentials_via_mimikatz_modules.yml +++ /dev/null @@ -1,126 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifites the use of Mimikatz modules attempting to perform Pass-the-Ticket, - Golden or Silver Kerberos ticket attacks and Skeleton Key attack. This behavior - is typically performed within interactive Mimikatz memory space, however it may - be identified on the command-line. A Pass-the-Ticket (ptt) attack is performed once - an adversary has established access to a single endpoint and retrieved the kerberos - ticket to now begin moving laterally using this method. Typically, it blends in - with logon activity as the ticket can be copied to another system and passed into - the current session effectively simulating a logon without any communication with - the Domain Controller. A Golden or Silver ticket attack requires some setup by the - adversary, but once performed it will simulate lateral based authentication to additional - endpoints.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to Mimikatz. -name: Applying Stolen Credentials via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -- https://adsecurity.org/?p=1275 -- https://adsecurity.org/?p=1515 -- https://adsecurity.org/?page_id=1821#KERBEROSPTT -- https://attack.mitre.org/software/S0002/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash -risk_message: Mimikatz malware is violating authentication processes by injecting - golden or silver Kerberos tickets or passing stolen authentication tokens. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, - /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true - OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) | eval start_time = timestamp, - end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is violating authentication processes by injecting golden - or silver Kerberos tickets or passing stolen authentication tokens. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1068 - - T1078 - - T1098 - - T1134 - - T1543 - - T1547 - - T1548 - - T1554 - - T1556 - - T1558 - - T1558.002 - - T1558.001 - - T1003 - - T1003.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - - cmd_line - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Applying Stolen Credentials via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test applying stolen credentials detections - file: endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml - name: Applying Stolen Credentials via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/complex/ssa___applying_stolen_credentials_via_powersploit_modules.yml deleted file mode 100644 index dacb73b8b0..0000000000 --- a/dist/ssa/complex/ssa___applying_stolen_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,121 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies commonly used PowerSploit modules that perform credential access, - spoofing of authentication processes, user impersonation and attempting to manipulate - tokens. Specifically, the following modules `Invoke-CredentialInjection`, `Invoke-TokenManipulation`, - `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` were identfiied - as modules used to access credentials. PowerSploit is an archived project on GitHub, - but much of its modules and scripts are still utilized today by adversaries. This - behavior is typically performed within interactive PowerShell sessions or injected - into processes, however it may be identified on the command-line.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 270b482d-2af2-448f-9923-9cf005f61be4 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to PowerSploit. -name: Applying Stolen Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -- https://attack.mitre.org/software/S0194/ -risk_message: PowerSploit malware is violating authentication by injecting stolen - credentials, manipulating authentication tokens or impersonating system or user - accounts. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true - OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, - /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is violating authentication by injecting stolen credentials, - manipulating authentication tokens or impersonating system or user accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1068 - - T1078 - - T1098 - - T1134 - - T1543 - - T1547 - - T1548 - - T1554 - - T1555 - - T1558 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - - cmd_line - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Applying Stolen Credentials via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test applying stolen credentials detections - file: endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml - name: Applying Stolen Credentials via PowerSploit - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml deleted file mode 100644 index 81bc5ed977..0000000000 --- a/dist/ssa/complex/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, that - verifies password strength. Adversaries have utilized this module to determine password - complexity or to identify accounts with weak passwords.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Assessment of Credential Strength via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. - Account attempting this operation is $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Test-PasswordQuality/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 85 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 30 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. - Account attempting this operation is $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - - T1087 - - T1201 - - T1552 - - T1555 - - T1059.001 - - T1059 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - - cmd_line - risk_score: 25 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___attempt_to_delete_services.yml b/dist/ssa/complex/ssa___attempt_to_delete_services.yml deleted file mode 100644 index 043cbf7607..0000000000 --- a/dist/ssa/complex/ssa___attempt_to_delete_services.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Teoderick Contreras, splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -description: The following analytic identifies Windows Service Control, `sc.exe`, - attempting to delete a service. This is typically identified in parallel with other - instances of service enumeration of attempts to stop a service and then delete it. - Adversaries utilize this technique to terminate security services or other related - services to continue there objective and evade detections. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: a0c8c292-d01a-11eb-aa18-acde48001122 -known_false_positives: It is possible administrative scripts may start/stop/delete - services. Filter as needed. -name: Attempt To Delete Services -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%delete%") AND process_name = "sc.exe" - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 8 - - CIS 13 - confidence: 60 - context: - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Persistence - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log - impact: 60 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. - mitre_attack_id: - - T1489 - - T1543 - - T1543.003 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 36 - risk_severity: medium - security_domain: endpoint -test: - name: Attempt To delete Services Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_del.log - file_name: sc_del.log - source: WinEventLog:Security - description: Test for usage of sc.exe to delete a service - file: endpoint/ssa___attempt_to_delete_services.yml - name: Attempt To delete Services - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/complex/ssa___attempt_to_disable_services.yml b/dist/ssa/complex/ssa___attempt_to_disable_services.yml deleted file mode 100644 index 869d013f4b..0000000000 --- a/dist/ssa/complex/ssa___attempt_to_disable_services.yml +++ /dev/null @@ -1,105 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -description: The following analytic identifies Windows Service Control, `sc.exe`, - attempting to disable a service. This is typically identified in parallel with other - instances of service enumeration of attempts to stop a service and then disable - it. Adversaries utilize this technique to terminate security services or other related - services to continue there objective and evade detections. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: afb31de4-d023-11eb-98d5-acde48001122 -known_false_positives: It is possible administrative scripts may start/stop/delete - services. Filter as needed. -name: Attempt To Disable Services -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -- https://app.any.run/tasks/c0f98850-af65-4352-9746-fbebadee4f05/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1562.001/T1562.001.md#atomic-test-14---disable-arbitrary-security-windows-service -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. -search: '| from read_ssa_enriched_events() | eval _datamodels=ucast(map_get(input_event, - "_datamodels"), "collection", []), body={} | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%disabled%") AND like(cmd_line, "%config%") - AND process_name="sc.exe" | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 9 - - CIS 8 - confidence: 60 - context: - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Persistence - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log - impact: 60 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable a service. - mitre_attack_id: - - T1489 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - risk_score: 36 - risk_severity: medium - security_domain: endpoint -test: - name: Attempt To Disable Services Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/sc_disable.log - file_name: sc_disable.log - source: WinEventLog:Security - description: Test for usage of sc.exe to disable a service - file: endpoint/ssa___attempt_to_disable_services.yml - name: Attempt To Disable Services - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml b/dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml deleted file mode 100644 index a27a74f132..0000000000 --- a/dist/ssa/complex/ssa___bcdedit_failure_recovery_modification.yml +++ /dev/null @@ -1,99 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search looks for flags passed to bcdedit.exe modifications to the - built-in Windows error recovery boot configurations. This is typically used by ransomware - to prevent recovery. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13 -known_false_positives: Administrators may modify the boot configuration. -name: BCDEdit Failure Recovery Modification -product: -- Splunk Behavioral Analytics -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md#atomic-test-4---windows---disable-windows-recovery-console-repair -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability - to recover the endpoint. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="bcdedit.exe" - AND (like (cmd_line, "%recoveryenabled%") AND like (cmd_line, "%no%")) | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - Ryuk Ransomware - - Ransomware - cis20: - - CIS 8 - confidence: 80 - context: - - Source:Endpoint - - Stage:Impact - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - impact: 100 - kill_chain_phases: - - Actions on Objectives - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting disable the ability - to recover the endpoint. - mitre_attack_id: - - T1490 - nist: - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: BCDEdit Failure Recovery Modification - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - description: Test detection of BCDEdit Failure Recovery Modification - file: endpoint/ssa___bcdedit_failure_recovery_modification.yml - name: BCDEdit Failure Recovery Modification - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml deleted file mode 100644 index 8b64d2eba1..0000000000 --- a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies modules within DSInternals that are used for extracting credentials - from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, `ConvertFrom-GPPrefPassword`, - `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, - `ConvertTo-LMHash`, `ConvertTo-NTHash` `ConvertTo-OrgIdHash` or `ConvertTo-UnicodePassword`. - Adversaries may use these modules for decrypting or transforming the stored credentials.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Credential Extraction indicative of use of DSInternals credential conversion - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is converting stolen credential material to a form - applicable to authentications. Operation is performed on the device $dest_device_id$, - by the account $dest_user_id$ via process $process_name$. -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true - OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, - /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true - OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, - /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true - OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, - /(?i)ConvertTo-UnicodePassword/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is converting stolen credential material to a form - applicable to authentications. Operation is performed on the device $dest_device_id$, - by the account $dest_user_id$ via process $process_name$. - mitre_attack_id: - - T1003 - - T1003.002 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml deleted file mode 100644 index f45b2993b6..0000000000 --- a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies modules of DSInternals being used on the associated endpoint. - Adversaries may use these modules for manipulating data related to Active Directory - and credentials.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Credential Extraction indicative of use of DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is accessing sensitive credential material such - as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, - /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true - OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, - /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true - OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, - /(?i)Get-SamPasswordPolicy/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is accessing sensitive credential material such as - KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ - mitre_attack_id: - - T1003 - - T1003.002 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml deleted file mode 100644 index 152bedd309..0000000000 --- a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. Mimikatz is a collection of tools and modules - commonly employed in Windows exploits.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 -known_false_positives: None identified. -name: Credential Extraction indicative of use of Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is extracting/decoding encoded credentials from stores - such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true - OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true - OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true - OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true - OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 95 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is extracting/decoding encoded credentials from stores - such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 66 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml b/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml deleted file mode 100644 index e6a8ff148f..0000000000 --- a/dist/ssa/complex/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. PowerSploit is a collection of Microsoft PowerShell - modules commonly employed in exploits.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 5f1186a4-e681-446e-851c-dc9574ad28eb -known_false_positives: None identified. -name: Credential Extraction indicative of use of PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is extracting encoded credentials or spoofing automated - logings. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true - OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true - OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, - /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true - OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, - /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is extracting encoded credentials or spoofing automated - logings. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___delete_a_net_user.yml b/dist/ssa/complex/ssa___delete_a_net_user.yml deleted file mode 100644 index ba622e4b1c..0000000000 --- a/dist/ssa/complex/ssa___delete_a_net_user.yml +++ /dev/null @@ -1,109 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This analytic will detect a suspicious net.exe/net1.exe command-line - to delete a user on a system. This technique may be use by an administrator for - legitimate purposes, however this behavior has been used in the wild to impair some - user or deleting adversaries tracks created during its lateral movement additional - systems. During triage, review parallel processes for additional behavior. Identify - any other user accounts created before or after. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed net.exe may be used. -id: 8776d79c-d26e-11eb-9a56-acde48001122 -known_false_positives: System administrators or scripts may delete user accounts via - this technique. Filter as needed. -name: Delete A Net User -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user - account. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%/delete%") AND (process_name="net1.exe" - OR process_name="net.exe") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 4 - - CIS 16 - confidence: 70 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log - impact: 70 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a user - account. - mitre_attack_id: - - T1531 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 49 - risk_severity: medium - security_domain: endpoint -test: - name: Delete A Net User Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_del.log - file_name: net_user_del.log - source: WinEventLog:Security - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1531/atomic_red_team/security.log - file_name: security.log - source: WinEventLog:Security - description: Test for usage of net.exe or net1.exe to delete net user - file: endpoint/ssa___delete_a_net_user.yml - name: Delete A Net User - pass_condition: '@count_gt(0)' -type: Anomaly -version: 3 diff --git a/dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml b/dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml deleted file mode 100644 index 82f434863b..0000000000 --- a/dist/ssa/complex/ssa___deny_permission_using_cacls_utility.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` - or `xcacls.exe` placing the deny permission on a file or directory. Adversaries - perform this behavior to prevent responders from reviewing or gaining access to - adversary files on disk. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. -id: b76eae28-cd25-11eb-9c92-acde48001122 -known_false_positives: System administrators may use cacls utilities but this is not - a common practice. Filter as needed. -name: Deny Permission using Cacls Utility -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to deny - a permission of a file or directory in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)deny/)=true - AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - cis20: - - CIS 14 - - CIS 16 - confidence: 70 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - impact: 50 - kill_chain_phases: - - Exploitation - message: A cacls process $process_name$ with commandline $cmd_line$ try to deny - a permission of a file or directory in host $dest_device_id$ - mitre_attack_id: - - T1222 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Deny Permission using Cacls Utility Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - file_name: all_icalc.log - source: WinEventLog:Security - description: Test for usage of cacls deny permission to a file(s) or folder(s) - file: endpoint/ssa___deny_permission_using_cacls_utility.yml - name: Deny Permission using Cacls Utility - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml deleted file mode 100644 index e31f5ae16e..0000000000 --- a/dist/ssa/complex/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ /dev/null @@ -1,87 +0,0 @@ -author: Jose Hernandez, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -description: The following analytic identifies credential dumping using comsvcs.dll - with `regsvr32.exe`. This technique is common with adversaries who would like to - dump the memory of lsass.exe and perform offline password cracking. -how_to_implement: You must be ingesting endpoint data that tracks process activity, - including Windows command line logging. You can see how we test this with [Event - Code 4688](https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=4688a) - on the [attack_range](https://github.com/splunk/attack_range/blob/develop/ansible/roles/windows_common/tasks/windows-enable-4688-cmd-line-audit.yml). -id: 76bb9e35-f314-4c3d-a385-83c72a13ce4e -known_false_positives: False positives should be limited, filter as needed. -name: Detect Dump LSASS Memory using comsvcs -product: -- Splunk Behavioral Analytics -references: -- https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Kheirkhabarov_Hunting_for_Credentials_Dumping_in_Windows_Environment.pdf -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.001/T1003.001.md#atomic-test-3---dump-lsassexe-memory-using-comsvcsdll -risk_message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ - by user $dest_device_user$. -search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_event, - "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), - "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", - null)), process=lower(ucast(map_get(input_event, "process"), "string", null)), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where process_name LIKE "%rundll32.exe%" AND match_regex(process, - /(?i)comsvcs.dll[,\s]+MiniDump/)=true | eval start_time = timestamp, end_time = - timestamp, entities = mvappend(machine), body=create_map(["event_id", event_id, - "process_name", process_name, "process", process]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Endpoint - cis20: - - CIS 8 - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: A dump of lsass.exe was attempted using comsvcs.dll on endpoint $dest_device_id$ - by user $dest_device_user$. - mitre_attack_id: - - T1003.003 - - T1003 - nist: - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _tenant - - _time - - dest_device_id - - process - risk_score: 70 - risk_severity: low - security_domain: endpoint -test: - name: Detect Dump LSASS Memory using comsvcs - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test credential dumping detections - file: endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml - name: Detect Dump LSASS Memory using comsvcs - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml b/dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml deleted file mode 100644 index f369662145..0000000000 --- a/dist/ssa/complex/ssa___detect_prohibited_applications_spawning_cmd_exe.yml +++ /dev/null @@ -1,103 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-10' -description: The following analytic identifies parent processes, browsers, Windows - terminal applications, Office Products and Java spawning cmd.exe. By its very nature, - many applications spawn cmd.exe natively or built into macros. Much of this will - need to be tuned to further enhance the risk. -how_to_implement: In order to successfully implement this analytic, you will need - endpoint process data from a EDR product or Sysmon. This search has been modified - to process raw sysmon data from attack_range's nxlogs on DSP. -id: c10a18cb-fd80-4ffa-a844-25026e0a0c94 -known_false_positives: There are circumstances where an application may legitimately - execute and interact with the Windows command-line interface. -name: Detect Prohibited Applications Spawning cmd exe -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1059/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event - that warrants investigating. -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) - | eval process_name=ucast(map_get(input_event, "process_name"), "string", null), - parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", - null)), cmd_line=lower(ucast(map_get(input_event, "process"),"string", null)), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event,"event_id"), "string", null) - | where process_name="cmd.exe" | rex field=parent_process "(?[^\\\\]+)$" - | where ParentBaseFileName="winword.exe" OR ParentBaseFileName="excel.exe" OR ParentBaseFileName="outlook.exe" - OR ParentBaseFileName="powerpnt.exe" OR ParentBaseFileName="visio.exe" OR ParentBaseFileName="mspub.exe" - OR ParentBaseFileName="acrobat.exe" OR ParentBaseFileName="acrord32.exe" OR ParentBaseFileName="iexplore.exe" - OR ParentBaseFileName="opera.exe" OR ParentBaseFileName="firefox.exe" OR (ParentBaseFileName="java.exe" - AND (cmd_line IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%patch1-Hotfix1a%")))) - OR ParentBaseFileName="powershell.exe" OR (ParentBaseFileName="chrome.exe" AND (cmd_line - IS NULL OR (cmd_line IS NOT NULL AND NOT like(cmd_line, "%chrome-extension%")))) - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "process_name", process_name, - "parent_process_name", parent_process, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Suspicious Command-Line Executions - cis20: - - CIS 8 - confidence: 50 - context: - - Source:Endpoint - - Stage:Defense Evasion - impact: 70 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$, producing a suspicious event - that warrants investigating. - mitre_attack_id: - - T1059 - nist: - - PR.PT - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Detect Prohibited Applications Spawning cmd exe Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/powershell_spawn_cmd/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Detect Prohibited Applications Spawning cmd exe - file: endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml - name: Detect Prohibited Applications Spawning cmd exe - pass_condition: '@count_gt(0)' -type: Anomaly -version: 2 diff --git a/dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml b/dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml deleted file mode 100644 index effffe33fc..0000000000 --- a/dist/ssa/complex/ssa___detect_rclone_command-line_usage.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-03' -description: This analytic identifies commonly used command-line arguments used by - `rclone.exe` to initiate a file transfer. Some arguments were negated as they are - specific to the configuration used by adversaries. In particular, an adversary may - list the files or directories of the remote file share using `ls` or `lsd`, which - is not indicative of malicious behavior. During triage, at this stage of a ransomware - event, exfiltration is about to occur or has already. Isolate the endpoint and continue - investigating by review file modifications and parallel processes. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: e8b74268-5454-11ec-a799-acde48001122 -known_false_positives: False positives should be limited as this is restricted to - the Rclone process name. Filter or tune the analytic as needed. -name: Detect RClone Command-Line Usage -product: -- Splunk Behavioral Analytics -references: -- https://redcanary.com/blog/rclone-mega-extortion/ -- https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html -- https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/ -- https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a remote - cloud service to move files or folders. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="rclone.exe" - AND (like (cmd_line, "%copy%") OR like (cmd_line, "%mega%")OR like (cmd_line, "%pcloud%") - OR like (cmd_line, "%ftp%") OR like (cmd_line, "%--config%") OR like (cmd_line, - "%--progress%") OR like (cmd_line, "%--no-check-certificate%") OR like (cmd_line, - "%--ignore-existing%") OR like (cmd_line, "%--auto-confirm%") OR like (cmd_line, - "%--transfers%") OR like (cmd_line, "%--multi-thread-streams%")) | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)) - | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - DarkSide Ransomware - - Ransomware - automated_detection_testing: passed - confidence: 70 - context: - - Source:Endpoint - - Stage:Exfiltration - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-security.log - impact: 50 - kill_chain_phases: - - Exfiltration - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to connect to a - remote cloud service to move files or folders. - mitre_attack_id: - - T1020 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___disable_net_user_account.yml b/dist/ssa/complex/ssa___disable_net_user_account.yml deleted file mode 100644 index 6e179bef39..0000000000 --- a/dist/ssa/complex/ssa___disable_net_user_account.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This analytic will identify a suspicious command-line that disables a - user account using the native `net.exe` or `net1.exe` utility to Windows. This technique - may used by the adversaries to interrupt availability of accounts and continue the - impact against the organization. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed net.exe/net1.exe may be - used. -id: ba858b08-d26c-11eb-af9b-acde48001122 -known_false_positives: System administrators or automated scripts may disable an account - but not a common practice. Filter as needed. -name: Disable Net User Account -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%/active:no%") AND like(cmd_line, "%user%") - AND (process_name="net1.exe" OR process_name="net.exe") | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - - Ransomware - cis20: - - CIS 4 - - CIS 16 - confidence: 70 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log - impact: 70 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to disable accounts. - mitre_attack_id: - - T1489 - - T1078 - nist: - - PR.AC - - PR.IP - observable: - - name: user - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 49 - risk_severity: medium - security_domain: endpoint -test: - name: Disable Net User Account Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/net_user_dis.log - file_name: net_user_dis.log - source: WinEventLog:Security - description: Test for usage of net.exe or net1.exe to disable net user - file: endpoint/ssa___disable_net_user_account.yml - name: Disable Net User Account - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml b/dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml deleted file mode 100644 index 0f154fa153..0000000000 --- a/dist/ssa/complex/ssa___dns_exfiltration_using_nslookup_app.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search is to detect potential DNS exfiltration using nslookup application. - This technique are seen in couple of malware and APT group to exfiltrated collected - data in a infected machine or infected network. This detection is looking for unique - use of nslookup where it tries to use specific record type, TXT, A, AAAA, that are - commonly used by attacker and also the retry parameter which is designed to query - C2 DNS multiple tries. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: 2452e632-9e0d-11eb-34ba-acde48001122 -known_false_positives: It is possible for some legitimate administrative utilities - to use similar cmd_line parameters. Filter as needed. -name: DNS Exfiltration Using Nslookup App -product: -- Splunk Behavioral Analytics -references: -- https://www.fireeye.com/blog/threat-research/2017/03/fin7_spear_phishing.html -- https://www.varonis.com/blog/dns-tunneling/ -- https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/ -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related - to DNS exfiltration. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="nslookup.exe" - AND (like (cmd_line, "%-querytype=%") OR like (cmd_line, "%-qt=%") OR like (cmd_line, - "%-q=%") OR like (cmd_line, "%-type=%") OR like (cmd_line, "%-retry=%")) | eval - start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, - "process_name", process_name, "parent_process_name", parent_process_name, "process_path", - process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Suspicious DNS Traffic - - Dynamic DNS - - Command and Control - - Data Exfiltration - automated_detection_testing: passed - confidence: 80 - context: - - Source:Endpoint - - Stage:Exfiltration - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log - impact: 90 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ performing activity related - to DNS exfiltration. - mitre_attack_id: - - T1048 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 72 - risk_severity: low - security_domain: endpoint -test: - name: DNS Exfiltration Using Nslookup App Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/nslookup_exfil/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - file: endpoint/ssa_dns_exfiltration_using_nslookup_app.yml - name: DNS Exfiltration Using Nslookup App - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___fsutil_zeroing_file.yml b/dist/ssa/complex/ssa___fsutil_zeroing_file.yml deleted file mode 100644 index 0efb8d94cc..0000000000 --- a/dist/ssa/complex/ssa___fsutil_zeroing_file.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search is to detect a suspicious fsutil process to zeroing a target - file. This technique was seen in lockbit ransomware where it tries to zero out its - malware path as part of its defense evasion after encrypting the compromised host. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed net.exe may be used. -id: f792cdc9-43ee-4429-a3c0-ffce4fed1a85 -known_false_positives: System administrators or scripts may delete user accounts via - this technique. Filter as needed. -name: Fsutil Zeroing File -product: -- Splunk Behavioral Analytics -references: -- https://app.any.run/tasks/e0ac072d-58c9-4f53-8a3b-3e491c7ac5db/ -- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/fsutil-file -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file deletion. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="fsutil.exe" - AND (like (cmd_line, "%setzerodata%")) | eval start_time=timestamp, end_time=timestamp, - entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, - "dest_device_id"), "string", null)), body=create_map(["event_id", event_id, "cmd_line", - cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, - "process_path", process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Ransomware - confidence: 90 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: [] - impact: 60 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ atempting to perform file - deletion. - mitre_attack_id: - - T1070 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 54 - risk_severity: low - security_domain: endpoint -test: - name: FSUtil Zeroing File - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/fsutil_file_zero/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - description: Test detection of FSUtil Zeroing File - file: endpoint/ssa___fsutil_zeroing_file.yml - name: FSUtil Zeroing File - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml b/dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml deleted file mode 100644 index 70f10dafc1..0000000000 --- a/dist/ssa/complex/ssa___grant_permission_using_cacls_utility.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: The following analytic identifies the use of `cacls.exe`, `icacls.exe` - or `xcacls.exe` placing the grant permission on a file or directory. Adversaries - perform this behavior to allow components of their files to run, however it allows - responders to review or gaining access to adversary files on disk. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed icacls.exe may be used. -id: c6da561a-cd29-11eb-ae65-acde48001122 -known_false_positives: System administrators may use cacls utilities but this is not - a common practice. Filter as needed. -name: Grant Permission Using Cacls Utility -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to grant - user a permission to a file or directory in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND match_regex(cmd_line, /(?i)grant/)=true - AND (process_name="cacls.exe" OR process_name="xcacls.exe" OR process_name="icacls.exe") - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - cis20: - - CIS 14 - - CIS 16 - confidence: 70 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - impact: 50 - kill_chain_phases: - - Exploitation - message: A cacls process $process_name$ with commandline $cmd_line$ try to grant - user a permission to a file or directory in host $dest_device_id$ - mitre_attack_id: - - T1222 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Grant Permission Using Cacls Utility Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - file_name: all_icalc.log - source: WinEventLog:Security - description: Test for usage of cacls grant permission to a file(s) or folder(s) - file: endpoint/ssa___grant_permission_using_cacls_utility.yml - name: Grant Permission Using Cacls Utility - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml deleted file mode 100644 index 341dc81365..0000000000 --- a/dist/ssa/complex/ssa___illegal_access_to_user_content_via_powersploit_modules.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegaly access user content, - such as key logging, audio recording, screenshots, tapping into http and RDP sessions, - etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 01fc7d91-eb0c-478e-8633-e4fa4904463a -known_false_positives: None identified. -name: Illegal Access To User Content via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is tapping into user content - microphone, camera, - ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR - match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true - OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, - /(?i)Get-WebConfig/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Exfiltration - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log - impact: 85 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is tapping into user content - microphone, camera, - ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1021 - - T1113 - - T1123 - - T1563 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 85 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_account_creation_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_account_creation_via_powersploit_modules.yml deleted file mode 100644 index 97237df015..0000000000 --- a/dist/ssa/complex/ssa___illegal_account_creation_via_powersploit_modules.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that create accounts illegaly.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 20fba62a-fa5b-46cc-b39f-473fa248fee2 -known_false_positives: None identified. -name: Illegal Account Creation via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is creating illegal domain accounts. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)New-DomainUser/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Persistence - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is creating illegal domain accounts. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1585 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Account Creation via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal account creation detections - file: endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml - name: Illegal Account Creation via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml deleted file mode 100644 index aa16051c53..0000000000 --- a/dist/ssa/complex/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml +++ /dev/null @@ -1,83 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that delete event logs.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b -known_false_positives: None identified. -name: Illegal Deletion of Logs via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is deleting event logs to cover tracks of malicious - activity. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Log Manipulation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is deleting event logs to cover tracks of malicious activity. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1070 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml deleted file mode 100644 index 4d6a3d0141..0000000000 --- a/dist/ssa/complex/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of DSInternals modules that enable or disable accounts illegaly.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 3e0f9962-9989-445f-878c-939443326b63 -known_false_positives: None identified. -name: Illegal Enabling or Disabling of Accounts via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is illegally enabling or disabling accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is illegally enabling or disabling accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml deleted file mode 100644 index 0b45aa84ef..0000000000 --- a/dist/ssa/complex/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml +++ /dev/null @@ -1,89 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of DSInternals modules for illegal management of Active Directoty - elements and policies.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: a587ca9f-c138-47b4-ba51-699f319b8cc5 -known_false_positives: None identified. -name: Illegal Management of Active Directory Elements and Policies via DSInternals - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is controlling infrastructure by modifying Active - Directory elements, domain controllers, and policies. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true - OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, - /(?i)Set-LsaPolicyInformation/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is controlling infrastructure by modifying Active Directory - elements, domain controllers, and policies. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1098 - - T1207 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml deleted file mode 100644 index 12c1053ff5..0000000000 --- a/dist/ssa/complex/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegal management of computers - and Active Directory elements.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 75760c11-7d48-4968-b828-013b299e8f6d -known_false_positives: None identified. -name: Illegal Management of Computers and Active Directory Elements via PowerSploit - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is controlling infrastructure by modifying Active - Directory elements or local Master Boot Records. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR - match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, - /(?i)Set-MasterBootRecord/)=true ) - - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is controlling infrastructure by modifying Active Directory - elements or local Master Boot Records. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1098 - - T1207 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml deleted file mode 100644 index 6ec2973e83..0000000000 --- a/dist/ssa/complex/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that illegaly elevate general privileges - or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent - WMI, access to OS objects under desired identities.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 88c10ee9-fe72-4bce-b343-5b129044b991 -known_false_positives: None identified. -name: Illegal Privilege Elevation and Persistence via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is planting attack persistence elements, altering - privileges and access controls. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true - OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true - OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Malicious PowerShell - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Command And Control - - Stage:Persistence - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is planting attack persistence elements, altering privileges - and access controls. Operation is performed at the device $dest_device_id$, by - the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1053 - - T1134 - - T1548 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Privilege Elevation and Persistence via PowerSploit modules - SSA - Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test privilege elevation and persistence detections - file: endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml - name: Illegal Privilege Elevation and Persistence via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml deleted file mode 100644 index 14b98b6333..0000000000 --- a/dist/ssa/complex/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for illegal privilege elevation.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 2f873b1f-6352-4844-b7b9-b419f09a42c7 -known_false_positives: None identified. -name: Illegal Privilege Elevation via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is setting highest privileges to malicious entities. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Privilege Escalation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is setting highest privileges to malicious entities. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1134 - - T1548 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Privilege Elevation via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal privilege elevation detections - file: endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml - name: Illegal Privilege Elevation via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml deleted file mode 100644 index 65e6678eaa..0000000000 --- a/dist/ssa/complex/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml +++ /dev/null @@ -1,100 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for illegal control over services and processes, - including the authentication service.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: aaf3adf1-73e1-4477-b4ee-3771898964f1 -known_false_positives: None identified. -name: Illegal Service and Process Control via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, - /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, - /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true - OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Service Abuse - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is controlling computer's processess and services. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1106 - - T1569 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Service and Process Control via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal service and process control detections - file: endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml - name: Illegal Service and Process Control via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/dist/ssa/complex/ssa___illegal_service_and_process_control_via_powersploit_modules.yml deleted file mode 100644 index 6766a7231c..0000000000 --- a/dist/ssa/complex/ssa___illegal_service_and_process_control_via_powersploit_modules.yml +++ /dev/null @@ -1,110 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegal control of services - and processes, such as installing or spoofing of malicious services, injecting malicious - code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to - service objects, etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 0e910e5b-309d-4bc3-8af2-0030c02aa353 -known_false_positives: None identified. -name: Illegal Service and Process Control via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true - OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, - /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true - OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, - /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true - OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, - /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true - OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, - /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true - ) - - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Service Abuse - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1055 - - T1106 - - T1569 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal service and process control detections - file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml - name: Illegal Service and Process Control via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml b/dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml deleted file mode 100644 index ae2e490edf..0000000000 --- a/dist/ssa/complex/ssa___modify_acls_permission_of_files_or_folders.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This analytic identifies suspicious modification of ACL permission to - a files or folder to make it available to everyone or to a specific user. This technique - may be used by the adversary to evade ACLs or protected files access. This changes - is commonly configured by the file or directory owner with appropriate permission. - This behavior raises suspicion if this command is seen on an endpoint utilized by - an account with no permission to do so. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. Tune and filter known instances where renamed cacls.exe may be used. -id: 9ae9a48a-cdbe-11eb-875a-acde48001122 -known_false_positives: System administrators may use this windows utility. filter - is needed. -name: Modify ACLs Permission Of Files Or Folders -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -risk_message: A cacls process $process_name$ with commandline $cmd_line$ try to modify - a permission of a file or directory in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line IS NOT NULL AND like(cmd_line, "%/G%") AND (match_regex(cmd_line, - /(?i)everyone:/)=true OR match_regex(cmd_line, /(?i)SYSTEM:/)=true) AND (process_name="cacls.exe" - OR process_name="xcacls.exe" OR process_name="icacls.exe") | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - XMRig - cis20: - - CIS 8 - - CIS 13 - confidence: 70 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - impact: 50 - kill_chain_phases: - - Exploitation - message: A cacls process $process_name$ with commandline $cmd_line$ try to modify - a permission of a file or directory in host $dest_device_id$ - mitre_attack_id: - - T1222 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 35 - risk_severity: medium - security_domain: endpoint -test: - name: Modify ACLs Permission Of Files Or Folders Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1222.001/ssa_cacls/all_icalc.log - file_name: all_icalc.log - source: WinEventLog:Security - description: Test for modifying permission of a file(s) or folder(s) using cacls - utility. - file: endpoint/ssa___modify_acls_permission_of_files_or_folders.yml - name: Modify ACLs Permission Of Files Or Folders - pass_condition: '@count_gt(0)' -type: Anomaly -version: 2 diff --git a/dist/ssa/complex/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml b/dist/ssa/complex/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml deleted file mode 100644 index c1f2707376..0000000000 --- a/dist/ssa/complex/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml +++ /dev/null @@ -1,62 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: [] -date: '2020-08-25' -description: Malicious mails can conduct phishing that induces readers to open attachment, - click links or trigger third party service. This detect uses Natural Language Processing - (NLP) approach to analyze an email message's content (Sender, Subject and Body) - and judge whether it is a phishing email. The detection adopts a deep learning (neural - network) model that employs character level embeddings plus LSTM layers to perform - classification. The model is pre-trained and then published as ONNX format. Current - sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json - User are expected to re-train the model by combining with their own training data - for better accuracy using the provided model file (SMLE notebook). DSP pipeline - then processes the email message and passes it as an event to Apply ML Models function, - which returns the probability of a phishing email. Current implementation assumes - the email is fed to DSP in JSON format contains at least email's sender, subject - and its message body, including reply content, if any. -how_to_implement: Events are fed to DSP contains at least email's sender, subject - and its message body. -id: 4b237388-dfa1-41a6-91d4-4de2d598376f -known_false_positives: Because of imbalance of anomaly data in training, the model - will less likely report false positive. Instead, the model is more prone to false - negative. Current best recall score is ~85% -name: Phishing Email Detection by Machine Learning Method - SSA -product: -- Splunk Behavioral Analytics -references: [] -search: '| from read_ssa_enriched_events() | eval eventLine=concat(ucast(map_get(input_event, - "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " - "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), - _time=map_get(input_event, "_time") | where eventLine IS NOT NULL | eval mapC={" - ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, - ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, - "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, - ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, - "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, - "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, - "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, - "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": - 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": - 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": - 119, "x": 120, "y": 121, "z": 122, "{": 123, "|": 124, "}": 125, "~": 126}, ml_in - = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, - 1)), "float") ) | apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" - path="s3://smle-experiments/models/phishing_email" | eval probability = mvindex(ml_out, - 0) | where probability > 0.5 | eval start_time=_time, end_time=_time, entities="TBD", - body="TBD" | select probability, body, entities, start_time, end_time | into write_ssa_detected_events();' -tags: - cis20: - - CIS 8 - kill_chain_phases: - - Actions on Objectives - mitre_attack_id: - - T1566 - nist: - - PR.PT - - DE.CM - product: - - Splunk Behavioral Analytics - risk_severity: low - security_domain: mail server -type: Anomaly -version: 1 diff --git a/dist/ssa/complex/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/complex/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml deleted file mode 100644 index a7053b9879..0000000000 --- a/dist/ssa/complex/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-04' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules that facilitate access probing with admin - credentials as well as probing access to system services.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: d405af5d-99f1-45af-8dfb-b8f98b764247 -known_false_positives: None identified. -name: Probing Access with Stolen Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is probing access with stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true - OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Privilege Escalation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is probing access with stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_user_id - - dest_device_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -test: - name: Probing Access with Stolen Credentials via PowerSploit modules - SSA Unit - test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test access probing with stolen credentials detections - file: endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml - name: Probing Access with Stolen Credentials via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml deleted file mode 100644 index af78d4cb23..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of accounts and groups and access - to them.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 -known_false_positives: None identified. -name: Reconnaissance and Access to Accounts and Groups via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and using specific accounts and groups. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and using specific accounts and groups. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1078 - - T1087 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml deleted file mode 100644 index 48aac644b9..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml +++ /dev/null @@ -1,109 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover accounts, groups and policies - that can be accessed or taken over.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 63422f8e-766c-468f-8133-2ba6795e263b -known_false_positives: None identified. -name: Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and using specific accounts, groups - and policies, such as the last logged on account, a local Net group, etc. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true - OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, - /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true - OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, - /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true - OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, - /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true - OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true - OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, - /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true - OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, - /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true - OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true - OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, - /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true - OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true - OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true - OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, - /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true - OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, - /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, - /(?i)Get-LastLoggedOn/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and using specific accounts, groups - and policies, such as the last logged on account, a local Net group, etc. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1087 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml deleted file mode 100644 index 9cd26d09f7..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml +++ /dev/null @@ -1,98 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules for reconnaissance and access to elements - of Active Directory infrastructure, such as domain identifiers, AD sites and forests, - and trust relations.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: db08ac40-ee14-43e9-9a75-dddd059ef812 -known_false_positives: None identified. -name: Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is seaching for or accessing Active Directory objects - such as domain sites, domain trusts, AD forests, etc. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR - match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true - OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true - OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, - /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true - OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true - OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true - OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, - /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true - OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is seaching for or accessing Active Directory objects - such as domain sites, domain trusts, AD forests, etc. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1199 - - T1482 - - T1590 - - T1591 - - T1595 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml deleted file mode 100644 index 9f677b78bb..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover computers, servers and domains - that can be accessed or taken over.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: fe1c4c5a-09f3-4b43-8129-560a7f38a08b -known_false_positives: None identified. -name: Reconnaissance and Access to Computers and Domains via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is seaching for or accessing domain controllers, - computers, file servers, etc. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR - match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true - OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true - OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, - /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is seaching for or accessing domain controllers, computers, - file servers, etc. Operation is performed at the device $dest_device_id$, by the - account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1592 - - T1590 - - T1087 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml deleted file mode 100644 index 4efdb3ecff..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml +++ /dev/null @@ -1,81 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of computers and servers and access - to them.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 -known_false_positives: None identified. -name: Reconnaissance and Access to Computers via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is collecting information about computers. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::ServerInfo/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is collecting information about computers. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ - mitre_attack_id: - - T1592 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml deleted file mode 100644 index 1637bfac4c..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml +++ /dev/null @@ -1,98 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover and access operating system - elements, such as processes, services, registry locations, security packages and - files.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c1d33ad9-1727-4f9f-a474-4adbe4fed68a -known_false_positives: None identified. -name: Reconnaissance and Access to Operating System Elements via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and tapping into ongoing processes, - mounted drives or other operating system elements. Operation is performed at the - device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true - OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, - /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR - match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true - OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, - /(?i)Get-RegistryMountedDrive/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and tapping into ongoing processes, - mounted drives or other operating system elements. Operation is performed at the - device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1057 - - T1083 - - T1592.002 - - T1046 - - T1012 - - T1007 - - T1047 - - T1592 - - T1518 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml deleted file mode 100644 index cc69c9c467..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml +++ /dev/null @@ -1,80 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery and access to services and processes.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 0243d37c-57c1-4182-bfd1-39b212255fc8 -known_false_positives: None identified. -name: Reconnaissance and Access to Processes and Services via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is listing processes and services. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is listing processes and services. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1007 - - T1046 - - T1057 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml deleted file mode 100644 index 4ea264cc5b..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery and access to network shares.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f -known_false_positives: None identified. -name: Reconnaissance and Access to Shared Resources via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::share/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Lateral Movement - - Stage:Collection - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml deleted file mode 100644 index dd4633a38e..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover and access network and distributed - file system shares.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 6b7ca431-6b1e-4b40-9589-21cb368e369e -known_false_positives: None identified. -name: Reconnaissance and Access to Shared Resources via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true - OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, - /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true - OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, - /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Lateral Movement - - Stage:Collection - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml deleted file mode 100644 index c79a306b71..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml +++ /dev/null @@ -1,101 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules that discover opportunities for malicious - access and persistence. Some examples include access to admin accounts, weak access - control policies, landing paths for dropping malicious software or data to exfiltrate, - registry locations to land autorun parameters, task scheduling opportunities, as - well as services and system files that can be compromised.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 -known_false_positives: None identified. -name: Reconnaissance of Access and Persistence Opportunities via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for an entry point into the infrastructure, - such as local admin accounts, opportunities to hijack processes, unattended install - files, or modifiable access objects. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true - OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, - /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true - OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, - /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true - OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, - /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true - OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, - /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true - OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, - /(?i)Get-UnquotedService/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for an entry point into the infrastructure, - such as local admin accounts, opportunities to hijack processes, unattended install - files, or modifiable access objects. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1053 - - T1068 - - T1078 - - T1543 - - T1547 - - T1574 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml deleted file mode 100644 index 4011dcfffe..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules for reconnaissance of connectivity.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 -known_false_positives: None identified. -name: Reconnaissance of Connectivity via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is performing port scans or searching for various - connectivity details such as DNS data, proxies, or ongoing RDP connections. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true - OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, - /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, - /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true - OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is performing port scans or searching for various connectivity - details such as DNS data, proxies, or ongoing RDP connections. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml deleted file mode 100644 index cbfc35bd95..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies reconnaissance of credential stores and use of CryptoAPI services by - Mimikatz modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 5facee5b-79e4-47ab-b0e6-c625acc0554f -known_false_positives: None identified. -name: Reconnaissance of Credential Stores and Services via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and accessing credential stores. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, - /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true - OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and accessing credential stores. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1098 - - T1590.001 - - T1078 - - T1589.001 - - T1590 - - T1068 - - T1589 - - T1590.003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml deleted file mode 100644 index c100454874..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml +++ /dev/null @@ -1,83 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules for assessment of presence of defensive tools.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 24b4e659-63a2-4e7b-89ac-87dd659c7110 -known_false_positives: None identified. -name: Reconnaissance of Defensive Tools via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is looking for presence of anti virus software. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-AVSignature/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 40 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is looking for presence of anti virus software. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1592.002 - - T1595.002 - - T1592 - - T1595 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 40 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml deleted file mode 100644 index a919f28981..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml +++ /dev/null @@ -1,82 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules for assessment of privilege escalation opportunities.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: b9b4492c-2af8-449b-beb4-b1b78d963321 -known_false_positives: None identified. -name: Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is engaging its privilege escalation module. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Invoke-PrivescAudit/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is engaging its privilege escalation module. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml deleted file mode 100644 index 0232e39486..0000000000 --- a/dist/ssa/complex/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of process or service hijacking - opportunities via Microsoft Detours compatibility. Microsoft Detours is an open - source library for intercepting, monitoring and instrumenting binary functions on - Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory - code for target functions. The Detours package also contains utilities to attach - arbitrary DLLs and data segments called payloads to any Win32 binary.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: fc5c1cbd-7494-4314-aad2-458d6fd4fada -known_false_positives: None identified. -name: Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -- https://en.wikipedia.org/wiki/Microsoft_Detours -risk_message: Mimikatz malware is looking for and invoking Microsoft Detours package - that enables spoofing of in-memory code. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)misc::detours/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is looking for and invoking Microsoft Detours package - that enables spoofing of in-memory code. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1543 - - T1055 - - T1574 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___resize_shadowstorage_volume.yml b/dist/ssa/complex/ssa___resize_shadowstorage_volume.yml deleted file mode 100644 index aeb81926a4..0000000000 --- a/dist/ssa/complex/ssa___resize_shadowstorage_volume.yml +++ /dev/null @@ -1,105 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: The following analytic identifies the resizing of shadowstorage using - vssadmin.exe to avoid the shadow volumes being made again. This technique is typically - found used by adversaries during a ransomware event and a precursor to deleting - the shadowstorage. -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: dbc30554-d27e-11eb-9e5e-acde48001122 -known_false_positives: System administrators may resize the shadowstorage for valid - purposes. Filter as needed. -name: Resize Shadowstorage Volume -product: -- Splunk Behavioral Analytics -references: -- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html -- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow - copy to perform offline password cracking. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND like(cmd_line, "%resize%") AND like(cmd_line, "%shadowstorage%") - AND like(cmd_line, "%maxsize%") AND process_name="vssadmin.exe" | eval start_time=timestamp, - end_time=timestamp, entities=mvappend(ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", process_name, - "parent_process_name", parent_process_name, "process_path", process_path]) | into - write_ssa_detected_events();' -tags: - analytic_story: - - Clop Ransomware - - Ransomware - cis20: - - CIS 10 - - CIS 13 - confidence: 80 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log - impact: 80 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to create a shadow - copy to perform offline password cracking. - mitre_attack_id: - - T1489 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 64 - risk_severity: low - security_domain: endpoint -test: - name: Resize Shadowstorage Volume Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ransomware_ttp/ssa_data1/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test for resizing the shadow storage of a machine - file: endpoint/ssa___resize_shadowstorage_volume.yml - name: Resize Shadowstorage Volume - pass_condition: '@count_gt(0)' -type: TTP -version: 3 diff --git a/dist/ssa/complex/ssa___sdelete_application_execution.yml b/dist/ssa/complex/ssa___sdelete_application_execution.yml deleted file mode 100644 index 53541e83fe..0000000000 --- a/dist/ssa/complex/ssa___sdelete_application_execution.yml +++ /dev/null @@ -1,110 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-15' -description: This analytic will detect the execution of sdelete.exe attempting to - delete potentially important files that may related to adversary or insider threats - to destroy evidence or information sabotage. Sdelete is a SysInternals utility meant - to securely delete files on disk. This tool is commonly used to clear tracks and - artifact on the targeted host. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, - confirm the latest CIM App 4.20 or higher is installed and the latest TA for the - endpoint product. -id: fcc52b9a-4616-11ec-8454-acde48001122 -known_false_positives: False positives should be limited, filter as needed. -name: Sdelete Application Execution -product: -- Splunk Behavioral Analytics -references: -- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1485/T1485.md -risk_message: Sdelete process $process_name$ executed on $dest_device_id$ attempting - to permanently delete files by $dest_user_id$. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event,"_time"), - "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), "string", - null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), process_path=ucast(map_get(input_event, "process_path"), "string", null), - parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), parent_cmd_line=ucast(map_get(input_event, "parent_process"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where cmd_line - IS NOT NULL AND process_name IS NOT NULL AND like(process_name, "%sdelete%") AND - (like (cmd_line, "%-c %") OR like (cmd_line, "%-f %")OR like (cmd_line, "%-p %") - OR like (cmd_line, "%-r %") OR like (cmd_line, "%-q %") OR like (cmd_line, "%-s - %") OR like (cmd_line, "%-z %") OR like (cmd_line, "%/accepteula%") OR like (cmd_line, - "%-nobanner%")OR like (cmd_line, "%.doc%")OR like (cmd_line, "%.xls%") OR like (cmd_line, - "%.ppt%")OR like (cmd_line, "%.rtf%") OR like (cmd_line, "%.pdf%") OR like (cmd_line, - "%.key%")OR like (cmd_line, "%.log%") OR like (cmd_line, "%.txt%") OR like (cmd_line, - "%.jpg%") OR like (cmd_line, "%.png%") OR like (cmd_line, "%.gif%") OR like (cmd_line, - "%.bmp%") OR like (cmd_line, "%.7z%") OR like (cmd_line, "%.zip%") OR like (cmd_line, - "%.rar%") OR like (cmd_line, "%.tar%") OR like (cmd_line, "%.gz%") OR like (cmd_line, - "%.xls%")) | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "process_path", process_path, "parent_process_name", parent_process_name, - "parent_cmd_line", parent_cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Information Sabotage - confidence: 70 - context: - - Source:Endpoint - - Stage:Execution - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log - impact: 60 - kill_chain_phases: - - Exploitation - message: Sdelete process $process_name$ executed on $dest_device_id$ attempting - to permanently delete files by $dest_user_id$. - mitre_attack_id: - - T1485 - - T1070.004 - - T1070 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest - - user - - parent_process_name - - parent_process - - process_name - - process - - process_id - - process_path - - cmd_line - risk_score: 42 - risk_severity: medium - security_domain: endpoint -test: - name: Sdelete Application Execution Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/security.log - file_name: security.log - source: WinEventLog:Security - description: Test for sdelete execution command - file: endpoint/ssa___sdelete_application_execution.yml - name: Sdelete Application Execution - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/complex/ssa___setting_credentials_via_dsinternals_modules.yml b/dist/ssa/complex/ssa___setting_credentials_via_dsinternals_modules.yml deleted file mode 100644 index f91f7f5062..0000000000 --- a/dist/ssa/complex/ssa___setting_credentials_via_dsinternals_modules.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via DSInternals modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c -known_false_positives: None identified. -name: Setting Credentials via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is accessing, using or setting Active Directory - or Azure credentials and accounts. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true - OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true - OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, - /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true - OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Source:Cloud Data - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is accessing, using or setting Active Directory or - Azure credentials and accounts. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via DSInternals modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - file_name: logAllDSInternalsModules.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_dsinternals_modules.yml - name: Setting Credentials via DSInternals modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___setting_credentials_via_mimikatz_modules.yml b/dist/ssa/complex/ssa___setting_credentials_via_mimikatz_modules.yml deleted file mode 100644 index f2771dd531..0000000000 --- a/dist/ssa/complex/ssa___setting_credentials_via_mimikatz_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via Mimikatz modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c8b84699-7652-4363-910f-efd1ca82f780 -known_false_positives: None identified. -name: Setting Credentials via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is accessing, using or setting account credentials. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is accessing, using or setting account credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_mimikatz_modules.yml - name: Setting Credentials via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___setting_credentials_via_powersploit_modules.yml b/dist/ssa/complex/ssa___setting_credentials_via_powersploit_modules.yml deleted file mode 100644 index 2cfe008d54..0000000000 --- a/dist/ssa/complex/ssa___setting_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via PowerSploit modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 07b2a501-f967-4ddc-9f56-2dce46dfce44 -known_false_positives: None identified. -name: Setting Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is setting passwords on Active Directory accounts. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Set-DomainUserPassword/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is setting passwords on Active Directory accounts. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml - name: Setting Credentials via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml b/dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml deleted file mode 100644 index 1d7a52b1dd..0000000000 --- a/dist/ssa/complex/ssa___wbadmin_delete_system_backups.yml +++ /dev/null @@ -1,102 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-07' -description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator - Tool) that delete backup files. This is typically used by ransomware to prevent - recovery. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: 71efbf52-4dbb-4c00-a520-306aa546cbb7 -known_false_positives: Administrators may modify the boot configuration. -name: WBAdmin Delete System Backups -product: -- Splunk Behavioral Analytics -references: -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1490/T1490.md -- https://thedfirreport.com/2020/10/08/ryuks-return/ -- https://attack.mitre.org/techniques/T1490/ -- https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/wbadmin -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system - backups. -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=lower(ucast(map_get(input_event, "process"), - "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), - "string", null)), process_path=ucast(map_get(input_event, "process_path"), "string", - null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="wbadmin.exe" - AND like (cmd_line, "%delete%") OR like (cmd_line, "%catalog%") OR like (cmd_line, - "%systemstatebackup%") | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name, "process_path", process_path]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Ryuk Ransomware - - Ransomware - cis20: - - CIS 8 - confidence: 50 - context: - - Source:Endpoint - - stage:Defense Evasion - dataset: [] - impact: 30 - kill_chain_phases: - - Exploitation - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete system - backups. - mitre_attack_id: - - T1490 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 15 - risk_severity: medium - security_domain: endpoint -test: - name: WBAdmin Delete System Backups - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1490/atomic_red_team/windows-sysmon.log - file_name: windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - description: Test detection of WBAdmin Delete System Backups - file: endpoint/ssa___wbadmin_delete_system_backups.yml - name: WBAdmin Delete System Backups - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml b/dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml deleted file mode 100644 index aaeeca58e6..0000000000 --- a/dist/ssa/complex/ssa___wevtutil_usage_to_clear_logs.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-06-15' -description: The wevtutil.exe application is the windows event log utility. This searches - for wevtutil.exe with parameters for clearing the application, security, setup, - powershell, sysmon, or system event logs. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: 5438113c-cdd9-11eb-93b8-acde48001122 -known_false_positives: The wevtutil.exe application is a legitimate Windows event - log utility. Administrators may use it to manage Windows event logs. -name: WevtUtil Usage To Clear Logs -product: -- Splunk Behavioral Analytics -references: -- https://www.splunk.com/en_us/blog/security/detecting-clop-ransomware.html -risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear - event logs in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND like(cmd_line, "% cl %") AND (match_regex(cmd_line, - /(?i)security/)=true OR match_regex(cmd_line, /(?i)system/)=true OR match_regex(cmd_line, - /(?i)sysmon/)=true OR match_regex(cmd_line, /(?i)application/)=true OR match_regex(cmd_line, - /(?i)setup/)=true OR match_regex(cmd_line, /(?i)powershell/)=true) AND process_name="wevtutil.exe" - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, - "process_name", process_name, "parent_process_name", parent_process_name, "process_path", - process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Log Manipulation - - Ransomware - - Clop Ransomware - cis20: - - CIS 8 - - CIS 13 - confidence: 90 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log - impact: 70 - kill_chain_phases: - - Exploitation - message: A wevtutil process $process_name$ with commandline $cmd_line$ to clear - event logs in host $dest_device_id$ - mitre_attack_id: - - T1070 - - T1070.001 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -test: - name: WevtUtil Usage To Clear Logs Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/clear_evt.log - file_name: clear_evt.log - source: WinEventLog:Security - description: Test for wevtutil clear logs command - file: endpoint/ssa___wevtutil_usage_to_clear_logs.yml - name: WevtUtil Usage To Clear Logs - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml b/dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml deleted file mode 100644 index 72fb55c1ca..0000000000 --- a/dist/ssa/complex/ssa___wevtutil_usage_to_disable_logs.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Teoderick Contreras, Splunk -datamodel: -- Endpoint_Processes -date: '2021-06-15' -description: This search is to detect execution of wevtutil.exe to disable logs. This - technique was seen in several ransomware to disable the event logs to evade alerts - and detections in compromised host. -how_to_implement: You must be ingesting data that records process activity from your - hosts to populate the Endpoint data model in the Processes node. You must also be - ingesting logs with both the process name and command line from your endpoints. - The command-line arguments are mapped to the "process" field in the Endpoint data - model. -id: a4bdc944-cdd9-11eb-ac97-acde48001122 -known_false_positives: network operator may disable audit event logs for debugging - purposes. -name: Wevtutil Usage To Disable Logs -product: -- Splunk Behavioral Analytics -references: -- https://www.bleepingcomputer.com/news/security/new-ransom-x-ransomware-used-in-texas-txdot-cyberattack/ -risk_message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable - event logs in host $dest_device_id$ -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line IS NOT NULL AND like(cmd_line, "% sl %") AND like(cmd_line, "%/e:false%") - AND process_name="wevtutil.exe" | eval start_time=timestamp, end_time=timestamp, - entities=mvappend(ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, - "dest_device_id"), "string", null)) | eval body=create_map(["event_id", event_id, - "cmd_line", cmd_line, "process_name", process_name, "parent_process_name", parent_process_name, - "process_path", process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Log Manipulation - - Ransomware - cis20: - - CIS 8 - - CIS 13 - confidence: 90 - context: - - source:endpoint - - stage: Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log - impact: 70 - kill_chain_phases: - - Exploitation - message: A wevtutil process $process_name$ with commandline $cmd_line$ to disable - event logs in host $dest_device_id$ - mitre_attack_id: - - T1070 - - T1070.001 - nist: - - PR.DS - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -test: - name: Wevtutil Usage To Disable Logs Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070.001/ssa_wevtutil/disable_evt.log - file_name: disable_evt.log - source: WinEventLog:Security - description: Test for wevtutil disable logs command - file: endpoint/ssa___wevtutil_usage_to_disable_logs.yml - name: Wevtutil Usage To Disable Logs - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml b/dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml deleted file mode 100644 index af6e699d71..0000000000 --- a/dist/ssa/complex/ssa___windows_curl_upload_to_remote_destination.yml +++ /dev/null @@ -1,115 +0,0 @@ -author: Michael Haag, Splunk -datamodel: -- Endpoint_Processes -date: '2021-12-03' -description: 'The following analytic identifies the use of Windows Curl.exe uploading - a file to a remote destination. \ - - `-T` or `--upload-file` is used when a file is to be uploaded to a remotge destination. - \ - - `-d` or `--data` POST is the HTTP method that was invented to send data to a receiving - web application, and it is, for example, how most common HTML forms on the web work. - \ - - HTTP multipart formposts are done with `-F`, but this appears to not be compatible - with the Windows version of Curl. Will update if identified adversary tradecraft. - \ - - Adversaries may use one of the three methods based on the remote destination and - what they are attempting to upload (zip vs txt). During triage, review parallel - processes for further behavior. In addition, identify if the upload was successful - in network logs. If a file was uploaded, isolate the endpoint and review.' -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint_Processess` datamodel. -id: cc8d046a-543b-11ec-b864-acde48001122 -known_false_positives: False positives may be limited to source control applications - and may be required to be filtered out. -name: Windows Curl Upload to Remote Destination -product: -- Splunk Behavioral Analytics -references: -- https://everything.curl.dev/usingcurl/uploads -- https://techcommunity.microsoft.com/t5/containers/tar-and-curl-come-to-windows/ba-p/382409 -- https://twitter.com/d1r4c/status/1279042657508081664?s=20 -risk_message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote - destination. -search: '| from read_ssa_enriched_events() | where "Endpoint_Processes" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - - | where cmd_line IS NOT NULL AND process_name IS NOT NULL AND process_name="curl.exe" - AND (like (cmd_line, "%-T %") OR like (cmd_line, "%--upload-file %")OR like (cmd_line, - "%-d %") OR like (cmd_line, "%--data %") OR like (cmd_line, "%-F %")) - - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | eval body=create_map(["event_id", event_id, "cmd_line", cmd_line, - "process_name", process_name, "parent_process_name", parent_process_name, "process_path", - process_path]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Ingress Tool Transfer - automated_detection_testing: passed - confidence: 100 - context: - - Source:Endpoint - - Stage:Defense Evasion - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log - impact: 80 - kill_chain_phases: - - Exfiltration - message: An instance of $parent_process_name$ spawning $process_name$ was identified - on endpoint $dest_device_id$ by user $dest_user_id$ uploading a file to a remote - destination. - mitre_attack_id: - - T1105 - observable: - - name: dest_user_id - role: - - Victim - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: parent_process_name - role: - - Parent Process - type: Parent Process - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - dest_device_id - - process_name - - parent_process_name - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Windows Curl Upload to Remote Destination Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - file: endpoint/ssa___windows_curl_upload_to_remote_destination.yml - name: Windows Curl Upload to Remote Destination - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___detect_kerberoasting.yml b/dist/ssa/srs/ssa___detect_kerberoasting.yml deleted file mode 100644 index 0d07185006..0000000000 --- a/dist/ssa/srs/ssa___detect_kerberoasting.yml +++ /dev/null @@ -1,94 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: -- Certificates -date: '2020-10-21' -description: This search detects a potential kerberoasting attack via service principal - name requests -how_to_implement: The test data is converted from Windows Security Event logs generated - from Attach Range simulation and used in SPL search and extended to SPL2 -id: dabdd6d7-3e10-42be-8711-4e124f7a3850 -known_false_positives: Older systems that support kerberos RC4 by default NetApp may - generate false positives -name: Detect Kerberoasting -product: -- Splunk Behavioral Analytics -references: -- Initial ESCU implementation by Jose Hernandez and Patrick Bareiss -risk_message: Kerberoasting malware is potentially applying stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), - EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, - "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), - ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, - "service_id"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where EventCode="4769" - AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" | first_time_event - input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] - | where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID - | eval start_time=_time, end_time=_time | eval body=create_map(["event_id", event_id, - "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, - "TicketEncryptionType", TicketEncryptionType]), entities = mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | select start_time, end_time, entities, body | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - cis20: - - CIS 8 - - CIS 16 - confidence: 20 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Kerberoasting malware is potentially applying stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1558.003 - - T1558 - nist: - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - service_name - - _time - - event_code - - ticket_encryption_type - - service_id - - ticket_options - risk_score: 14 - risk_severity: medium - security_domain: endpoint -test: - name: Detect Kerberoasting - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test detection of kerberoasting - file: endpoint/ssa___detect_kerberoasting.yml - name: Detect kerberoasting - pass_condition: '@count_eq(0)' -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml b/dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml deleted file mode 100644 index 8a239045f5..0000000000 --- a/dist/ssa/srs/ssa___excessive_number_of_office_files_copied.yml +++ /dev/null @@ -1,64 +0,0 @@ -author: Patrick Bareiss, Splunk -datamodel: -- Endpoint_Filesystem -date: '2021-12-07' -description: This detection detects a high amount of office file copied. This can - be an indicator for a malicious insider. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Filesytem` node. -id: 3c6594a9-8df6-45a1-9357-d73b62083c63 -known_false_positives: user may copy a lot of office fies from one folder to another -name: Excessive Number of Office Files Copied -product: -- Splunk Behavioral Analytics -references: [] -risk_message: High number of files copied -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", - null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, - "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) - | where "Endpoint_Filesystem" IN(_datamodels) | where action="created" | where like(file_name, - "%.doc%") OR like(file_name, "%.xls%") OR like(file_name, "%.ppt%") | stats count(file_name) - AS count BY dest_user_id, dest_device_id, span(timestamp, 10m) | where count > 20 - | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, - dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' -tags: - analytic_story: [] - confidence: 80 - context: - - Source:Endpoint - - Stage:Exfitration - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log - impact: 90 - kill_chain_phases: - - Exploitation - message: High number of files copied - mitre_attack_id: - - T1048.003 - product: - - Splunk Behavioral Analytics - required_fields: - - action - - process - - file_name - - file_path - risk_score: 72 - risk_severity: low - security_domain: endpoint -test: - name: Excessive Number of Office Files Copied Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/mass_file_creation/windows-sysmon.log - file_name: sysmon.log - source: xmlwineventlog - description: Test for Excessive Number of Office Files Copied - file: endpoint/ssa___excessive_number_of_office_files_copied.yml - name: Excessive Number of Office Files Copied - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml b/dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml deleted file mode 100644 index 5bed7361d2..0000000000 --- a/dist/ssa/srs/ssa___first_time_seen_command_line_argument.yml +++ /dev/null @@ -1,89 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This search looks for command-line arguments that use a `/c` parameter - to execute a command that has not previously been seen. This is an implementation - on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following - analytic identifies first time seen command-line arguments on a single endpoint. - The analytic looks for arguments instantiated by `cmd.exe /c` and the associated - command-line. Adversaries automate or spawn multiple processes using this method, - this analytic may assist with identifying the first time it's been found on this - endpoint.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 -known_false_positives: Legitimate programs use command-line arguments to execute. - Verify the command-line arguments to check what command/program is being executed. - Filtering will be needed. -name: First time seen command line argument -product: -- Splunk Behavioral Analytics -references: [] -risk_message: A process $process_name$ ha been identified in the environment with - a command-line $cmd_line$ not previously seen before on host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), - "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), - cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, - "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, - "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" - */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, "\\PATH"), - /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, - /\d+/, "N"), event_id=ucast(map_get(input_event, "event_id"), "string", null) | - where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* - \/[cC] .*/)=true | select process_name, cmd_line, cmd_line_norm, timestamp, dest_device_id, - dest_user_id | first_time_event input_columns=["cmd_line_norm"] | where first_time_cmd_line_norm - | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 3 - - CIS 8 - confidence: 60 - context: - - source:endpoint - - stage: Defense Evasion - impact: 50 - kill_chain_phases: - - Command and Control - - Actions on Objectives - message: A process $process_name$ ha been identified in the environment with a command-line - $cmd_line$ not previously seen before on host $dest_device_id$ - mitre_attack_id: - - T1059 - - T1202 - nist: - - PR.PT - - DE.CM - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - - cmd_line - risk_score: 30 - risk_severity: medium - security_domain: endpoint -type: Anomaly -version: 4 diff --git a/dist/ssa/srs/ssa___high_file_deletion_frequency.yml b/dist/ssa/srs/ssa___high_file_deletion_frequency.yml deleted file mode 100644 index d8d355b0a6..0000000000 --- a/dist/ssa/srs/ssa___high_file_deletion_frequency.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Patrick Bareiss, Splunk -datamodel: -- Endpoint_Filesystem -date: '2021-12-07' -description: This detection detects a high amount of file deletions in a short time - for specific file types. This can be an indicator for a malicious insider. -how_to_implement: To successfully implement this search you need to be ingesting information - on process that include the name of the process responsible for the changes from - your endpoints into the `Endpoint` datamodel in the `Filesytem` node. -id: b6200efd-13bd-4336-920a-057b25bbcfaf -known_false_positives: user may delete bunch of pictures or files in a folder. -name: High File Deletion Frequency -product: -- Splunk Behavioral Analytics -references: -- https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html -- https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html -risk_message: High frequency file deletion activity detected on host $Computer$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval action=ucast(map_get(input_event, "action"), "string", - null), process=ucast(map_get(input_event, "process"), "string", null), file_name=ucast(map_get(input_event, - "file_name"), "string", null), file_path=ucast(map_get(input_event, "file_path"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) - | where "Endpoint_Filesystem" IN(_datamodels) | where action="deleted" | where like(file_name, - "%.cmd") OR like(file_name, "%.ini") OR like(file_name, "%.gif") OR like(file_name, - "%.jpg") OR like(file_name, "%.jpeg") OR like(file_name, "%.db") OR like(file_name, - "%.doc%") OR like(file_name, "%.ps1") OR like(file_name, "%.xls%") OR like(file_name, - "%.ppt%") OR like(file_name, "%.bmp") OR like(file_name, "%.zip") OR like(file_name, - "%.rar") OR like(file_name, "%.7z") OR like(file_name, "%.chm") OR like(file_name, - "%.png") OR like(file_name, "%.log") OR like(file_name, "%.vbs") OR like(file_name, - "%.js") | stats count(file_name) AS count BY dest_user_id, dest_device_id, span(timestamp, - 10m) | where count > 20 | eval start_time=window_start, end_time=window_end, entities=mvappend(dest_user_id, - dest_device_id), body=create_map(["count", count]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Clop Ransomware - confidence: 80 - context: - - Source:Endpoint - - Stage:Execution - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log - impact: 90 - kill_chain_phases: - - Exploitation - message: High frequency file deletion activity detected on host $Computer$ - mitre_attack_id: - - T1485 - observable: - - name: user - role: - - Victim - type: User - - name: Computer - role: - - Victim - type: Endpoint - - name: deleted_files - role: - - Target - type: File Name - product: - - Splunk Behavioral Analytics - required_fields: - - action - - process - - file_name - - file_path - risk_score: 72 - risk_severity: low - security_domain: endpoint -test: - name: High File Deletion Frequency Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/excessive_file_deletions/windows-sysmon.log - file_name: sysmon.log - source: xmlwineventlog - description: Test for High File Deletion Frequency - file: endpoint/ssa___high_file_deletion_frequency.yml - name: High File Deletion Frequency - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 diff --git a/dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml b/dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml deleted file mode 100644 index 5995bc4c02..0000000000 --- a/dist/ssa/srs/ssa___more_than_usual_number_of_lolbas_applications_in_short_time_period.yml +++ /dev/null @@ -1,95 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-08-25' -description: Attacker activity may compromise executing several LOLBAS applications - in conjunction to accomplish their objectives. We are looking for more than usual - LOLBAS applications over a window of time, by building profiles per machine. -how_to_implement: Collect endpoint data such as sysmon or 4688 events. -id: 59c0dd70-169c-4900-9a1f-bfcf13302f93 -known_false_positives: 'Some administrative tasks may involve multiple use of LOLBAS - applications in a short period of time. This might trigger false positives at the - beginning when it hasn''t collected yet enough data to construct the baseline. - - ' -name: More than usual number of LOLBAS applications in short time period -product: -- Splunk Behavioral Analytics -references: -- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -risk_message: A system process $process_name$ with commandline $cmd_line$ spawn iin - short period of time in host $dest_device_id$ -search: ' | from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, - "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, - "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | where process_name=="regsvcs.exe" OR process_name=="ftp.exe" - OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" - OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" - OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" - OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" - OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" - OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" - OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" - OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" - OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" - OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" - OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" - OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" - OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" - OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" - OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" - OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" - OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" - OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" - OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" - OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR - process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" - OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" - OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" - OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" - OR process_name=="msconfig.exe" | stats count(process_name) as lolbas_counter by - device,span(timestamp, 300s) | eval lolbas_counter=lolbas_counter*1.0 | rename window_end - as timestamp | adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" - window=2419200000L | where label AND quantile>0.99 | eval start_time = window_start, - end_time = timestamp, entities = mvappend(device), body=create_map(["lolbas_counter", - lolbas_counter, "quantile", quantile, "device", device]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - confidence: 50 - context: - - source:endpoint - - stage: Defense Evasion - impact: 50 - kill_chain_phases: - - Exploitation - message: A system process $process_name$ with commandline $cmd_line$ spawn iin short - period of time in host $dest_device_id$ - mitre_attack_id: - - T1059 - - T1053 - nist: - - PR.PT - - DE.CM - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - _time - - process_name - risk_score: 25 - risk_severity: medium - security_domain: endpoint -type: Anomaly -version: 2 diff --git a/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml b/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml deleted file mode 100644 index e1415eadc5..0000000000 --- a/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_at_the_destination_device.yml +++ /dev/null @@ -1,102 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Authentication -date: '2021-11-30' -description: This detection identifies potential Pass the Token or Pass the Hash credential - stealing. We detect the main side effect of these attacks, which is a transition - from the dominant Kerberos logins to rare NTLM logins for a given user, as reported - by a detination device. -how_to_implement: You must be ingesting Windows Security logs from endpoint devices, - i.e., destinations of interest. Please make sure that event ID 4624 is being logged. -id: 82e76b80-5cdb-4899-9b43-85dbe777b36d -known_false_positives: Environments in which NTLM is used extremely rarely and for - benign purposes (such as a rare use of SMB shares). -name: Potential Pass the Token or Hash Observed at the Destination Device -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1550/002/ -- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ -risk_message: Potential lateral movement and credential stealing via Pass the Token - or Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the destination device $dest_device_id$ -search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - dest_user=lower(ucast(map_get(input_event, "dest_user_primary_artifact"), "string", - null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", null), - dest_device_id= ucast(map_get(input_event, "dest_device_id"), "string", null), - signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", null)), - authentication_method= lower(ucast(map_get(input_event, "authentication_method"), - "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) - - | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") - AND dest_user_id != null AND dest_device_id != null - - | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method - == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - - | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as - startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as - endNTLMTime by dest_user_id, dest_user, dest_device_id, span(timestamp, 86400s) - - | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND - (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - - | eval start_time=ucast(startNTLMTime, "long", null), end_time=ucast(endNTLMTime, - "long", null), entities=mvappend(dest_user_id, dest_device_id), body=create_map(["event_id", - event_id, "total_kerberos", totalKerberos, "total_ntlm", totalNtlm, "analysis_start_time", - startTime, "analysis_end_time", endTime, "pth_start_time", startNTLMTime, "pth_end_time", - endNTLMTime]) - - | into write_ssa_detected_events();' -tags: - analytic_story: - - Active Directory Lateral Movement - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Stage:Lateral Movement - impact: 80 - kill_chain_phases: - - Lateral Movement - message: Potential lateral movement and credential stealing via Pass the Token or - Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the destination device $dest_device_id$ - mitre_attack_id: - - T1550 - - T1550.002 - nist: - - PR.PT - - PR.AT - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Other - type: Hostname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - signature_id - - dest_user - - dest_user_id - - dest_device_id - - authentication_method - risk_score: 72 - risk_severity: low - security_domain: endpoint -type: TTP -version: 3 diff --git a/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml b/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml deleted file mode 100644 index 74810e4d36..0000000000 --- a/dist/ssa/srs/ssa___potential_pass_the_token_or_hash_observed_by_an_event_collecting_device.yml +++ /dev/null @@ -1,103 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Authentication -date: '2021-11-05' -description: This detection identifies potential Pass the Token or Pass the Hash credential - stealing. We detect the main side effect of these attacks, which is a transition - from the dominant Kerberos logins to rare NTLM logins for a given user, as reported - by an event-collecting device (i.e., a specific domain controller or an endpoint - destination). -how_to_implement: You must be ingesting Windows Security logs from devices of interest - - at least from domain controllers. Please make sure that event ID 4624 is being - logged. -id: 1058ba3e-a698-49bc-a1e5-7cedece4ea87 -known_false_positives: Environments in which NTLM is used extremely rarely and for - benign purposes (such as a rare use of SMB shares). -name: Potential Pass the Token or Hash Observed by an Event Collecting Device -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/techniques/T1550/002/ -- https://www.offensive-security.com/metasploit-unleashed/psexec-pass-hash/ -risk_message: Potential lateral movement and credential stealing via Pass the Token - or Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the logging device $origin_device_id$ -search: '| from read_ssa_enriched_events() | where "Authentication" IN(_datamodels) - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - dest_user= lower(ucast(map_get(input_event, "dest_user_primary_artifact"), - "string", null)), dest_user_id= ucast(map_get(input_event, "dest_user_id"), "string", - null), origin_device_id= ucast(map_get(input_event, "origin_device_id"), "string", - null), signature_id= lower(ucast(map_get(input_event, "signature_id"), "string", - null)), authentication_method= lower(ucast(map_get(input_event, "authentication_method"), - "string", null)), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where signature_id = "4624" AND (authentication_method="ntlmssp" OR authentication_method="kerberos") - AND dest_user_id != null AND origin_device_id != null - - | eval isKerberos=if(authentication_method == "kerberos", 1, 0), isNtlm=if(authentication_method - == "ntlmssp", 1, 0), timeNTLM=if(isNtlm > 0, timestamp, null) - - | stats sum(isKerberos) as totalKerberos, sum(isNtlm) as totalNtlm, min(timestamp) as - startTime, min(timeNTLM) as startNTLMTime, max(timestamp) as endTime, max(timeNTLM) as - endNTLMTime by dest_user_id, dest_user, origin_device_id, span(timestamp, 86400s) - - | where NOT dest_user="-" AND totalKerberos > 0 AND totalNtlm > 0 AND endTime - - startTime > 1800000 AND (totalKerberos > 10 * totalNtlm AND totalKerberos > 50) AND - (endTime - startTime) > 3 * (endNTLMTime - startNTLMTime) - - | eval start_time=startNTLMTime, end_time=endNTLMTime, entities=mvappend(dest_user_id, - origin_device_id), body=create_map(["event_id", event_id, "total_kerberos", totalKerberos, - "total_ntlm", totalNtlm, "analysis_start_time", startTime, "analysis_end_time", - endTime, "detection_start_time", startNTLMTime, "detection_end_time", endNTLMTime]) - - | into write_ssa_detected_events();' -tags: - analytic_story: - - Active Directory Lateral Movement - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 80 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Stage:Lateral Movement - impact: 80 - kill_chain_phases: - - Lateral Movement - message: Potential lateral movement and credential stealing via Pass the Token or - Pass the Hash techniques. Operation is performed via credentials of the account - $dest_user_id$ and observed by the logging device $origin_device_id$ - mitre_attack_id: - - T1550 - - T1550.002 - nist: - - PR.PT - - PR.AT - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: origin_device_id - role: - - Other - type: Hostname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - signature_id - - dest_user - - dest_user_id - - origin_device_id - - authentication_method - risk_score: 64 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml b/dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml deleted file mode 100644 index 4f0ce19970..0000000000 --- a/dist/ssa/srs/ssa___rare_parent-child_process_relationship.yml +++ /dev/null @@ -1,88 +0,0 @@ -author: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: An attacker may use LOLBAS tools spawned from vulnerable applications - not typically used by system administrators. This analytic leverages the Splunk - Streaming ML DSP plugin to find rare parent/child relationships. The list of application - has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -how_to_implement: Collect endpoint data such as sysmon or 4688 events. -id: cf090c78-bcc6-11eb-8529-0242ac130003 -known_false_positives: Some custom tools used by administrators could be used rarely - to launch remotely applications. This might trigger false positives at the beginning - when it has not collected yet enough data to construct the baseline. -name: Rare Parent-Child Process Relationship -product: -- Splunk Behavioral Analytics -references: -- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval parent_process=lower(ucast(map_get(input_event, - "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, - "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where parent_process_name!=null | select parent_process_name, process_name, cmd_line, - timestamp, dest_device_id, dest_user_id | conditional_anomaly conditional="parent_process_name" - target="process_name" | where (process_name="powershell.exe" OR process_name="regsvcs.exe" - OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" - OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" - OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" - OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" - OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" - OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" - OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" - OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" - OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" - OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" - OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" - OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" - OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" - OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" - OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" - OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" - OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" - OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" - OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" - OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" - OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR - process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" - OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" - OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" - OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") - | eval input = (-1)*log(output) | adaptive_threshold algorithm="gaussian" threshold=0.001 - window=604800000L | where label AND input > mean | eval start_time = timestamp, - end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = - create_map(["process_name", process_name, "parent_process_name", parent_process_name, - "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", - cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1203 - - T1059 - - T1053 - - T1072 - nist: - - PR.PT - - DE.CM - product: - - Splunk Behavioral Analytics - required_fields: - - process - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - cmd_line - risk_severity: low - security_domain: endpoint -type: Anomaly -version: 2 diff --git a/dist/ssa/srs/ssa___unusually_long_command_line.yml b/dist/ssa/srs/ssa___unusually_long_command_line.yml deleted file mode 100644 index 7431805fa7..0000000000 --- a/dist/ssa/srs/ssa___unusually_long_command_line.yml +++ /dev/null @@ -1,87 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-06' -description: Command lines that are extremely long may be indicative of malicious - activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin - to help identify command lines with lengths that are unusual for a given user. This - detection is inspired on Unusually Long Command Line authored by Rico Valdez. -how_to_implement: You must be ingesting sysmon endpoint data that monitors command - lines. -id: 58f43aba-1775-445e-b19c-be2b87d83ae3 -known_false_positives: This detection may flag suspiciously long command lines when - there is not sufficient evidence (samples) for a given process that this detection - is tracking; or when there is high variability in the length of the command line - for the tracked process. Also, some legitimate applications may use long command - lines. Such is the case of Ansible, that encodes Powershell scripts using long base64. - Attackers may use this technique to obfuscate their payloads. -name: Unusually Long Command Line -product: -- Splunk Behavioral Analytics -references: [] -risk_message: A process $process_name$ with a long commandline $cmd_line$ executed - in host $dest_device_id$ -search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval cmd_line=ucast(map_get(input_event, "process"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), - process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line!=null and dest_user_id!=null | eval - cmd_line_norm=replace(cast(cmd_line, "string"), /\s(--?\w+)|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, - /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, - ""))) | select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, - input | adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 - | where label AND quantile>0.99 | first_time_event input_columns=["dest_device_id", - "cmd_line"] | where first_time_dest_device_id_cmd_line | eval start_time = timestamp, - end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", - event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - confidence: 40 - context: - - source:endpoint - - stage: Defense Evasion - impact: 30 - kill_chain_phases: - - Actions on Objectives - message: A process $process_name$ with a long commandline $cmd_line$ executed in - host $dest_device_id$ - nist: - - PR.PT - - DE.CM - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 12 - risk_severity: medium - security_domain: endpoint -test: - name: Unusually Long Command Line - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/unusally_cmd_line/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test unusually long command lines - file: endpoint/ssa___unusually_long_command_line.yml - name: Unusually Long Command Line - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 From 2197a6986c77e4efb9a8579ef6360df6b0e5c101 Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 10 Jan 2022 17:45:57 -0500 Subject: [PATCH 5/9] removed deprecated detections from ssa package --- bin/generate.py | 50 +++---- ...tolen_credentials_via_mimikatz_modules.yml | 126 ------------------ ...en_credentials_via_powersploit_modules.yml | 121 ----------------- ...ntial_strength_via_dsinternals_modules.yml | 93 ------------- ..._of_fgdump_and_cachedump_with_s_option.yml | 100 -------------- ..._of_fgdump_and_cachedump_with_v_option.yml | 93 ------------- ...cative_of_lazagne_command_line_options.yml | 85 ------------ ...nternals_credential_conversion_modules.yml | 104 --------------- ...dicative_of_use_of_dsinternals_modules.yml | 106 --------------- ..._indicative_of_use_of_mimikatz_modules.yml | 90 ------------- ...dicative_of_use_of_powersploit_modules.yml | 91 ------------- ...crosoft_debuggers_peek_into_the_kernel.yml | 95 ------------- ...ft_debuggers_via_z_command_line_option.yml | 91 ------------- ...present_in_powersploit_and_dsinternals.yml | 86 ------------ dist/ssa/srs/ssa___detect_pass_the_hash.yml | 92 ------------- ...o_user_content_via_powersploit_modules.yml | 92 ------------- ...count_creation_via_powersploit_modules.yml | 93 ------------- ..._deletion_of_logs_via_mimikatz_modules.yml | 83 ------------ ...ng_of_accounts_via_dsinternals_modules.yml | 85 ------------ ...s_and_policies_via_dsinternals_modules.yml | 89 ------------- ...ctory_elements_via_powersploit_modules.yml | 90 ------------- ...nd_persistence_via_powersploit_modules.yml | 104 --------------- ...ivilege_elevation_via_mimikatz_modules.yml | 97 -------------- ...d_process_control_via_mimikatz_modules.yml | 100 -------------- ...rocess_control_via_powersploit_modules.yml | 110 --------------- ...en_credentials_via_powersploit_modules.yml | 96 ------------- ...counts_and_groups_via_mimikatz_modules.yml | 85 ------------ ...s_and_policies_via_powersploit_modules.yml | 109 --------------- ...infrastructure_via_powersploit_modules.yml | 98 -------------- ...rs_and_domains_via_powersploit_modules.yml | 90 ------------- ...cess_to_computers_via_mimikatz_modules.yml | 81 ----------- ...ystem_elements_via_powersploit_modules.yml | 98 -------------- ...sses_and_services_via_mimikatz_modules.yml | 80 ----------- ..._shared_resources_via_mimikatz_modules.yml | 85 ------------ ...ared_resources_via_powersploit_modules.yml | 90 ------------- ..._opportunities_via_powersploit_modules.yml | 101 -------------- ...f_connectivity_via_powersploit_modules.yml | 90 ------------- ...ores_and_services_via_mimikatz_modules.yml | 91 ------------- ...efensive_tools_via_powersploit_modules.yml | 83 ------------ ..._opportunities_via_powersploit_modules.yml | 82 ------------ ...ing_opportunities_via_mimikatz_modules.yml | 90 ------------- ...ng_credentials_via_dsinternals_modules.yml | 106 --------------- ...tting_credentials_via_mimikatz_modules.yml | 96 ------------- ...ng_credentials_via_powersploit_modules.yml | 96 ------------- 44 files changed, 27 insertions(+), 4086 deletions(-) delete mode 100644 dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml delete mode 100644 dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml delete mode 100644 dist/ssa/srs/ssa___detect_pass_the_hash.yml delete mode 100644 dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml delete mode 100644 dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml delete mode 100644 dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml delete mode 100644 dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml diff --git a/bin/generate.py b/bin/generate.py index 84b03d31a9..7080c1468b 100644 --- a/bin/generate.py +++ b/bin/generate.py @@ -111,34 +111,38 @@ def generate_ssa_yaml(detections, TEMPLATE_PATH, OUTPUT_PATH): os.makedirs(OUTPUT_PATH + '/srs/') for d in detections: - # check if the search contains "stats", "first_time_event", or "adaptive_threshold" which would make it a complex pipeline - pattern = re.compile('stats|first_time_event|adaptive_threshold') - - if re.findall("stats|first_time_event|adaptive_threshold", d['search']): - # it is a complex pipeline - manifest_file = OUTPUT_PATH + '/complex/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' + # skip deprecated + if 'deprecated' in d and d['deprecated']: + continue else: - # it is a simple pipeline can be placed on SRS (Simple Rule Service) - manifest_file = OUTPUT_PATH + '/srs/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' + # check if the search contains "stats", "first_time_event", or "adaptive_threshold" which would make it a complex pipeline + pattern = re.compile('stats|first_time_event|adaptive_threshold') - # remove unused fields - del d['risk'] - del d['deployment'] - del d['mappings'] - del d['savedsearch_annotations'] + if re.findall("stats|first_time_event|adaptive_threshold", d['search']): + # it is a complex pipeline + manifest_file = OUTPUT_PATH + '/complex/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' + else: + # it is a simple pipeline can be placed on SRS (Simple Rule Service) + manifest_file = OUTPUT_PATH + '/srs/ssa___' + d['name'].lower().replace(" ", "_") + '.yml' - # add detection test - test_file = 'ssa___' + d['name'].lower().replace(" ", "_") + '.test.yml' - for file in glob.glob('tests/*/*'): - if test_file == file.split("/")[-1]: - with open(file, 'r') as file: - test_yaml = yaml.safe_load(file) - d['test'] = test_yaml + # remove unused fields + del d['risk'] + del d['deployment'] + del d['mappings'] + del d['savedsearch_annotations'] - with open(manifest_file, 'w') as file: - documents = yaml.dump(d, file, sort_keys=True) + # add detection test + test_file = 'ssa___' + d['name'].lower().replace(" ", "_") + '.test.yml' + for file in glob.glob('tests/*/*'): + if test_file == file.split("/")[-1]: + with open(file, 'r') as file: + test_yaml = yaml.safe_load(file) + d['test'] = test_yaml - return True + with open(manifest_file, 'w') as file: + documents = yaml.dump(d, file, sort_keys=True) + + return OUTPUT_PATH def generate_savedsearches_conf(detections, deployments, TEMPLATE_PATH, OUTPUT_PATH): ''' diff --git a/dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml deleted file mode 100644 index c2d7b5f6be..0000000000 --- a/dist/ssa/srs/ssa___applying_stolen_credentials_via_mimikatz_modules.yml +++ /dev/null @@ -1,126 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifites the use of Mimikatz modules attempting to perform Pass-the-Ticket, - Golden or Silver Kerberos ticket attacks and Skeleton Key attack. This behavior - is typically performed within interactive Mimikatz memory space, however it may - be identified on the command-line. A Pass-the-Ticket (ptt) attack is performed once - an adversary has established access to a single endpoint and retrieved the kerberos - ticket to now begin moving laterally using this method. Typically, it blends in - with logon activity as the ticket can be copied to another system and passed into - the current session effectively simulating a logon without any communication with - the Domain Controller. A Golden or Silver ticket attack requires some setup by the - adversary, but once performed it will simulate lateral based authentication to additional - endpoints.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 759a653f-cb92-40f9-94c9-ec4e47b0f709 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to Mimikatz. -name: Applying Stolen Credentials via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -- https://adsecurity.org/?p=1275 -- https://adsecurity.org/?p=1515 -- https://adsecurity.org/?page_id=1821#KERBEROSPTT -- https://attack.mitre.org/software/S0002/ -- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1550.002/T1550.002.md#atomic-test-1---mimikatz-pass-the-hash -risk_message: Mimikatz malware is violating authentication processes by injecting - golden or silver Kerberos tickets or passing stolen authentication tokens. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", - null), event_id=ucast(map_get(input_event, "event_id"), "string", null) | where - cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, - /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true - OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) | eval start_time = timestamp, - end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), - "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), - body=create_map(["event_id", event_id, "cmd_line", cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is violating authentication processes by injecting golden - or silver Kerberos tickets or passing stolen authentication tokens. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1068 - - T1078 - - T1098 - - T1134 - - T1543 - - T1547 - - T1548 - - T1554 - - T1556 - - T1558 - - T1558.002 - - T1558.001 - - T1003 - - T1003.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - - cmd_line - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Applying Stolen Credentials via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test applying stolen credentials detections - file: endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml - name: Applying Stolen Credentials via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml deleted file mode 100644 index dacb73b8b0..0000000000 --- a/dist/ssa/srs/ssa___applying_stolen_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,121 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies commonly used PowerSploit modules that perform credential access, - spoofing of authentication processes, user impersonation and attempting to manipulate - tokens. Specifically, the following modules `Invoke-CredentialInjection`, `Invoke-TokenManipulation`, - `Invoke-UserImpersonation`, `Get-System`, and `Invoke-RevertToSelf` were identfiied - as modules used to access credentials. PowerSploit is an archived project on GitHub, - but much of its modules and scripts are still utilized today by adversaries. This - behavior is typically performed within interactive PowerShell sessions or injected - into processes, however it may be identified on the command-line.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 270b482d-2af2-448f-9923-9cf005f61be4 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to PowerSploit. -name: Applying Stolen Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -- https://attack.mitre.org/software/S0194/ -risk_message: PowerSploit malware is violating authentication by injecting stolen - credentials, manipulating authentication tokens or impersonating system or user - accounts. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true - OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, - /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is violating authentication by injecting stolen credentials, - manipulating authentication tokens or impersonating system or user accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1068 - - T1078 - - T1098 - - T1134 - - T1543 - - T1547 - - T1548 - - T1554 - - T1555 - - T1558 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - - cmd_line - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Applying Stolen Credentials via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test applying stolen credentials detections - file: endpoint/ssa___applying_stolen_credentials_via_powersploit_modules.yml - name: Applying Stolen Credentials via PowerSploit - pass_condition: '@count_gt(0)' -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml deleted file mode 100644 index 81bc5ed977..0000000000 --- a/dist/ssa/srs/ssa___assessment_of_credential_strength_via_dsinternals_modules.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-24' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies the use of a DSInternals module, `Test-PasswordQuality`, that - verifies password strength. Adversaries have utilized this module to determine password - complexity or to identify accounts with weak passwords.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 5526d3a4-2497-4e8d-9d3c-7a34c9aace2f -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Assessment of Credential Strength via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. - Account attempting this operation is $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Test-PasswordQuality/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 85 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 30 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. - Account attempting this operation is $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - - T1087 - - T1201 - - T1552 - - T1555 - - T1059.001 - - T1059 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - - cmd_line - risk_score: 25 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml deleted file mode 100644 index 889f60f282..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option.yml +++ /dev/null @@ -1,100 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies the use of CacheDump with the `-s` parameter to dump cached - credentials on the associated endpoint. Adversaries use Cachedump as it is a publicly-available - tool that extracts cached password hashes from a system''s registry.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 312582f2-5e91-42c1-a275-cd67f31373c8 -known_false_positives: False positives will be limited as this analytic targets specific - credential dumping process names. Filter as needed. -name: Credential Extraction indicative of FGDump and CacheDump with s option -product: -- Splunk Behavioral Analytics -references: -- https://attack.mitre.org/software/S0119/ -- https://en.kali.tools/all/?tool=182 -- http://foofus.net/goons/fizzgig/fgdump/ -- https://attack.mitre.org/software/S0120/ -risk_message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$. -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND process_name != null AND parent_process_name != null - AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, - /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true - AND match_regex(cmd_line, /(?i)\-s/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$. - mitre_attack_id: - - T1003 - - T1003.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml deleted file mode 100644 index 2cb20aa5bd..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies the use of CacheDump with the `-v` parameter to dump cached - credentials on the associated endpoint. Adversaries use Cachedump as it is a publicly-available - tool that extracts cached password hashes from a system''s registry.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 3c40b0ef-a03f-460a-9484-e4b9117cbb38 -known_false_positives: False positives will be limited as this analytic targets specific - credential dumping process names. Filter as needed. -name: Credential Extraction indicative of FGDump and CacheDump with v option -product: -- Splunk Behavioral Analytics -references: [] -risk_message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, - /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true - AND match_regex(cmd_line, /(?i)\-v/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is accessing stored credentials via FGDump or CacheDump - tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ - mitre_attack_id: - - T1003 - - T1003.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml deleted file mode 100644 index 4c2c36d0c0..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_indicative_of_lazagne_command_line_options.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. LaZagne is a tool that extracts various kinds - of credentials from a local computer, including account passwords, domain passwords, - browser passwords, etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 341975fa-4ad0-4f01-9acc-df4f69742db7 -known_false_positives: None identified. -name: Credential Extraction indicative of Lazagne command line options -product: -- Splunk Behavioral Analytics -references: [] -risk_message: Lazagne malware is extracting/decoding encoded credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, - /(?i)all\s+\-oA\s+\-output/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Lazagne malware is extracting/decoding encoded credentials. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ - mitre_attack_id: - - T1003 - - T1555 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml deleted file mode 100644 index 8b64d2eba1..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies modules within DSInternals that are used for extracting credentials - from Active Directory. Modules include `ConvertFrom-ADManagedPasswordBlob`, `ConvertFrom-GPPrefPassword`, - `ConvertFrom-UnicodePasswor`, `ConvertTo-GPPrefPassword`,`ConvertTo-KerberosKey`, - `ConvertTo-LMHash`, `ConvertTo-NTHash` `ConvertTo-OrgIdHash` or `ConvertTo-UnicodePassword`. - Adversaries may use these modules for decrypting or transforming the stored credentials.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 73e23834-c7ad-4860-bfd0-7d8ffe6527c2 -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Credential Extraction indicative of use of DSInternals credential conversion - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is converting stolen credential material to a form - applicable to authentications. Operation is performed on the device $dest_device_id$, - by the account $dest_user_id$ via process $process_name$. -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true - OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, - /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true - OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, - /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true - OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, - /(?i)ConvertTo-UnicodePassword/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is converting stolen credential material to a form - applicable to authentications. Operation is performed on the device $dest_device_id$, - by the account $dest_user_id$ via process $process_name$. - mitre_attack_id: - - T1003 - - T1003.002 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml deleted file mode 100644 index f45b2993b6..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_dsinternals_modules.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-29' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. The following - analytic identifies modules of DSInternals being used on the associated endpoint. - Adversaries may use these modules for manipulating data related to Active Directory - and credentials.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: 5d2172f0-8a7d-4ecd-aad9-2dcc95699e0d -known_false_positives: None identified as this is strictly identifying known command-line - attributes related to DSInternals. -name: Credential Extraction indicative of use of DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -- https://attack.mitre.org/techniques/T1059/001/ -risk_message: DSInternals tool kit is accessing sensitive credential material such - as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, - /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true - OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, - /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true - OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true - OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, - /(?i)Get-SamPasswordPolicy/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: DSInternals tool kit is accessing sensitive credential material such as - KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via process $process_name$ - mitre_attack_id: - - T1003 - - T1003.002 - - T1059.001 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: process_name - role: - - Child Process - type: Process - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - - cmd_line - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 2 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml deleted file mode 100644 index 152bedd309..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_mimikatz_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. Mimikatz is a collection of tools and modules - commonly employed in Windows exploits.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 966b635f-98e8-4aa4-9b49-47ed2cedcc85 -known_false_positives: None identified. -name: Credential Extraction indicative of use of Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is extracting/decoding encoded credentials from stores - such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true - OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true - OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true - OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true - OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 95 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is extracting/decoding encoded credentials from stores - such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 66 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml b/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml deleted file mode 100644 index e6a8ff148f..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_indicative_of_use_of_powersploit_modules.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. PowerSploit is a collection of Microsoft PowerShell - modules commonly employed in exploits.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 5f1186a4-e681-446e-851c-dc9574ad28eb -known_false_positives: None identified. -name: Credential Extraction indicative of use of PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is extracting encoded credentials or spoofing automated - logings. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true - OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true - OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, - /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true - OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, - /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is extracting encoded credentials or spoofing automated - logings. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml b/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml deleted file mode 100644 index 82a297f80d..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_peek_into_the_kernel.yml +++ /dev/null @@ -1,95 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, - livekd and windbg, can be leveraged to read credential material directly from memory - and process dumps.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c20bb8ec-e1b0-4640-b0ef-3a4c54f8c112 -known_false_positives: Although unlikely, using debuggers this way may be indicative - of developers analyzing crash dumps of their code. Note, even for developers this - is an unusual way of working on code - debuggers are mostly used to step through - code, not analyze its crash dumps. -name: Credential Extraction native Microsoft debuggers peek into the kernel -product: -- Splunk Behavioral Analytics -references: -- https://medium.com/@clermont1050/covid-19-cyber-infection-c615ead7c29 -risk_message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, by - the account $dest_user_id$ via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, - "parent_process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line != null AND parent_process_name != null AND process_name - != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, - /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true - AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name, "parent_process_name", parent_process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml b/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml deleted file mode 100644 index 2c56028283..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_native_microsoft_debuggers_via_z_command_line_option.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, - livekd and windbg, can be leveraged to read credential material directly from memory - and process dumps.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: adc51a77-90c9-4358-b43c-f10dd1a27d05 -known_false_positives: Although unlikely, using debuggers this way may be indicative - of developers analyzing crash dumps of their code. Note, even for developers this - is an unusual way of working on code - debuggers are mostly used to step through - code, not analyze its crash dumps. -name: Credential Extraction native Microsoft debuggers via z command line option -product: -- Splunk Behavioral Analytics -references: [] -risk_message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, by - the account $dest_user_id$ via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, - "process_name"), "string", null), event_id=ucast(map_get(input_event, "event_id"), - "string", null) | where cmd_line != null AND process_name != null AND ( match_regex(process_name, - /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, - /(?i)\-z\s+/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Unusual Processes - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Malicious actor is extracting/decoding encoded credentials via Microsoft's - native debugging tools. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml b/dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml deleted file mode 100644 index 46f99c3fb1..0000000000 --- a/dist/ssa/srs/ssa___credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals.yml +++ /dev/null @@ -1,86 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-18' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. Credential - extraction is often an illegal recovery of credential material from secured authentication - resources and repositories. This process may also involve decryption or other transformations - of the stored credential material. PowerSploit and DSInternals are common exploit - APIs offering PowerShell modules for various exploits of Windows and Active Directory - environments.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: e4f126b5-e6bc-4a5c-b1a8-d07bc6c4a49f -known_false_positives: None identified. -name: Credential Extraction via Get-ADDBAccount module present in PowerSploit and - DSInternals -product: -- Splunk Behavioral Analytics -references: [] -risk_message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount - module. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND match_regex(cmd_line, - /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\|]+/)=true - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - confidence: 90 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount - module. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1003 - nist: - - PR.IP - - PR.AC - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 63 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___detect_pass_the_hash.yml b/dist/ssa/srs/ssa___detect_pass_the_hash.yml deleted file mode 100644 index 54ff68c628..0000000000 --- a/dist/ssa/srs/ssa___detect_pass_the_hash.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: -- Authentication -date: '2020-10-21' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This search - looks for specific authentication events from the Windows Security Event logs to - detect potential attempts using Pass-the-Hash technique.' -how_to_implement: The test data is converted from Windows Security Event logs generated - from Attach Range simulation and used in SPL search and extended to SPL2 -id: 7cd8b9fa-6b0c-424f-92a6-9c5287a72f5f -known_false_positives: Legitimate logon activity by authorized NTLM systems may be - detected by this search. Please investigate as appropriate. -name: Detect Pass the Hash -product: -- Splunk Behavioral Analytics -references: -- Initial ESCU implementation by Bhavin Patel and Patrick Bareiss -risk_message: Potential use of the pass the hash/token attacks that spoof authentication. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: ' | from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) - | eval signature_id=map_get(input_event, "signature_id"), authentication_type=map_get(input_event, - "authentication_type"), authentication_method=map_get(input_event, "authentication_method"), - origin_device_domain=map_get(input_event, "origin_device_domain"), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - - | where (authentication_type="3" AND authentication_method="NtLmSsp") OR (authentication_type="9" - AND authentication_method="seclogo") - - | eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "authentication_type", authentication_type, - "authentication_method", authentication_method]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Lateral Movement - cis20: - - CIS 3 - - CIS 5 - - CIS 16 - confidence: 20 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Potential use of the pass the hash/token attacks that spoof authentication. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1550 - - T1550.002 - nist: - - PR.PT - - PR.AT - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - signature_id - - authentication_type - - _time - - authentication_method - - origin_device_domain - - dest_user_id - - dest_device_id - risk_score: 16 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml deleted file mode 100644 index 341dc81365..0000000000 --- a/dist/ssa/srs/ssa___illegal_access_to_user_content_via_powersploit_modules.yml +++ /dev/null @@ -1,92 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegaly access user content, - such as key logging, audio recording, screenshots, tapping into http and RDP sessions, - etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 01fc7d91-eb0c-478e-8633-e4fa4904463a -known_false_positives: None identified. -name: Illegal Access To User Content via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is tapping into user content - microphone, camera, - ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR - match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true - OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, - /(?i)Get-WebConfig/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Exfiltration - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log - impact: 85 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is tapping into user content - microphone, camera, - ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1021 - - T1113 - - T1123 - - T1563 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 85 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml deleted file mode 100644 index 97237df015..0000000000 --- a/dist/ssa/srs/ssa___illegal_account_creation_via_powersploit_modules.yml +++ /dev/null @@ -1,93 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that create accounts illegaly.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 20fba62a-fa5b-46cc-b39f-473fa248fee2 -known_false_positives: None identified. -name: Illegal Account Creation via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is creating illegal domain accounts. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)New-DomainUser/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Persistence - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is creating illegal domain accounts. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1585 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Account Creation via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal account creation detections - file: endpoint/ssa___illegal_account_creation_via_powersploit_modules.yml - name: Illegal Account Creation via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml deleted file mode 100644 index aa16051c53..0000000000 --- a/dist/ssa/srs/ssa___illegal_deletion_of_logs_via_mimikatz_modules.yml +++ /dev/null @@ -1,83 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that delete event logs.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 4ddb3b0d-f95f-4ae2-b4e8-663296453a7b -known_false_positives: None identified. -name: Illegal Deletion of Logs via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is deleting event logs to cover tracks of malicious - activity. Operation is performed at the device $dest_device_id$, by the account - $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Log Manipulation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is deleting event logs to cover tracks of malicious activity. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1070 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml deleted file mode 100644 index 4d6a3d0141..0000000000 --- a/dist/ssa/srs/ssa___illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of DSInternals modules that enable or disable accounts illegaly.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 3e0f9962-9989-445f-878c-939443326b63 -known_false_positives: None identified. -name: Illegal Enabling or Disabling of Accounts via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is illegally enabling or disabling accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is illegally enabling or disabling accounts. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml deleted file mode 100644 index 0b45aa84ef..0000000000 --- a/dist/ssa/srs/ssa___illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules.yml +++ /dev/null @@ -1,89 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of DSInternals modules for illegal management of Active Directoty - elements and policies.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: a587ca9f-c138-47b4-ba51-699f319b8cc5 -known_false_positives: None identified. -name: Illegal Management of Active Directory Elements and Policies via DSInternals - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is controlling infrastructure by modifying Active - Directory elements, domain controllers, and policies. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true - OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, - /(?i)Set-LsaPolicyInformation/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is controlling infrastructure by modifying Active Directory - elements, domain controllers, and policies. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1098 - - T1207 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml deleted file mode 100644 index 12c1053ff5..0000000000 --- a/dist/ssa/srs/ssa___illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegal management of computers - and Active Directory elements.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 75760c11-7d48-4968-b828-013b299e8f6d -known_false_positives: None identified. -name: Illegal Management of Computers and Active Directory Elements via PowerSploit - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is controlling infrastructure by modifying Active - Directory elements or local Master Boot Records. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR - match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, - /(?i)Set-MasterBootRecord/)=true ) - - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is controlling infrastructure by modifying Active Directory - elements or local Master Boot Records. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1098 - - T1207 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml deleted file mode 100644 index 6ec2973e83..0000000000 --- a/dist/ssa/srs/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml +++ /dev/null @@ -1,104 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that illegaly elevate general privileges - or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent - WMI, access to OS objects under desired identities.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 88c10ee9-fe72-4bce-b343-5b129044b991 -known_false_positives: None identified. -name: Illegal Privilege Elevation and Persistence via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is planting attack persistence elements, altering - privileges and access controls. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true - OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true - OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Malicious PowerShell - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Command And Control - - Stage:Persistence - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is planting attack persistence elements, altering privileges - and access controls. Operation is performed at the device $dest_device_id$, by - the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1053 - - T1134 - - T1548 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Privilege Elevation and Persistence via PowerSploit modules - SSA - Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test privilege elevation and persistence detections - file: endpoint/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml - name: Illegal Privilege Elevation and Persistence via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml deleted file mode 100644 index 14b98b6333..0000000000 --- a/dist/ssa/srs/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml +++ /dev/null @@ -1,97 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for illegal privilege elevation.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 2f873b1f-6352-4844-b7b9-b419f09a42c7 -known_false_positives: None identified. -name: Illegal Privilege Elevation via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is setting highest privileges to malicious entities. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Privilege Escalation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Privilege Escalation - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is setting highest privileges to malicious entities. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1134 - - T1548 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Privilege Elevation via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal privilege elevation detections - file: endpoint/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml - name: Illegal Privilege Elevation via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml deleted file mode 100644 index 65e6678eaa..0000000000 --- a/dist/ssa/srs/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml +++ /dev/null @@ -1,100 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for illegal control over services and processes, - including the authentication service.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: aaf3adf1-73e1-4477-b4ee-3771898964f1 -known_false_positives: None identified. -name: Illegal Service and Process Control via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, - /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, - /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true - OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Service Abuse - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Command And Control - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is controlling computer's processess and services. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1055 - - T1106 - - T1569 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Service and Process Control via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal service and process control detections - file: endpoint/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml - name: Illegal Service and Process Control via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml b/dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml deleted file mode 100644 index 6766a7231c..0000000000 --- a/dist/ssa/srs/ssa___illegal_service_and_process_control_via_powersploit_modules.yml +++ /dev/null @@ -1,110 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-09' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that enable illegal control of services - and processes, such as installing or spoofing of malicious services, injecting malicious - code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to - service objects, etc.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 0e910e5b-309d-4bc3-8af2-0030c02aa353 -known_false_positives: None identified. -name: Illegal Service and Process Control via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true - OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, - /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true - OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, - /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true - OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, - /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true - OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, - /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true - ) - - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Service Abuse - - Malicious PowerShell - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is controlling computer's processess and services. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1055 - - T1106 - - T1569 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Illegal Service and Process Control via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal service and process control detections - file: endpoint/ssa___illegal_service_and_process_control_via_powersploit_modules.yml - name: Illegal Service and Process Control via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml b/dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml deleted file mode 100644 index a7053b9879..0000000000 --- a/dist/ssa/srs/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-04' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules that facilitate access probing with admin - credentials as well as probing access to system services.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: d405af5d-99f1-45af-8dfb-b8f98b764247 -known_false_positives: None identified. -name: Probing Access with Stolen Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is probing access with stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true - OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Privilege Escalation - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is probing access with stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_user_id - - dest_device_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -test: - name: Probing Access with Stolen Credentials via PowerSploit modules - SSA Unit - test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test access probing with stolen credentials detections - file: endpoint/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml - name: Probing Access with Stolen Credentials via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml deleted file mode 100644 index af78d4cb23..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of accounts and groups and access - to them.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 1bce67aa-3fc4-4886-9089-67f0bfebbef6 -known_false_positives: None identified. -name: Reconnaissance and Access to Accounts and Groups via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and using specific accounts and groups. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and using specific accounts and groups. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1078 - - T1087 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml deleted file mode 100644 index 48aac644b9..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules.yml +++ /dev/null @@ -1,109 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover accounts, groups and policies - that can be accessed or taken over.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 63422f8e-766c-468f-8133-2ba6795e263b -known_false_positives: None identified. -name: Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and using specific accounts, groups - and policies, such as the last logged on account, a local Net group, etc. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true - OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, - /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true - OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, - /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true - OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, - /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true - OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true - OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, - /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true - OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, - /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true - OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true - OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, - /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true - OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true - OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true - OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, - /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true - OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, - /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, - /(?i)Get-LastLoggedOn/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and using specific accounts, groups - and policies, such as the last logged on account, a local Net group, etc. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1078 - - T1087 - - T1484 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml deleted file mode 100644 index 9cd26d09f7..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules.yml +++ /dev/null @@ -1,98 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules for reconnaissance and access to elements - of Active Directory infrastructure, such as domain identifiers, AD sites and forests, - and trust relations.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: db08ac40-ee14-43e9-9a75-dddd059ef812 -known_false_positives: None identified. -name: Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit - modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is seaching for or accessing Active Directory objects - such as domain sites, domain trusts, AD forests, etc. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR - match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true - OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true - OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, - /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true - OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true - OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true - OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, - /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true - OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is seaching for or accessing Active Directory objects - such as domain sites, domain trusts, AD forests, etc. Operation is performed at - the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1199 - - T1482 - - T1590 - - T1591 - - T1595 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml deleted file mode 100644 index 9f677b78bb..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover computers, servers and domains - that can be accessed or taken over.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: fe1c4c5a-09f3-4b43-8129-560a7f38a08b -known_false_positives: None identified. -name: Reconnaissance and Access to Computers and Domains via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is seaching for or accessing domain controllers, - computers, file servers, etc. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR - match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true - OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true - OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, - /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is seaching for or accessing domain controllers, computers, - file servers, etc. Operation is performed at the device $dest_device_id$, by the - account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1592 - - T1590 - - T1087 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml deleted file mode 100644 index 4efdb3ecff..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_computers_via_mimikatz_modules.yml +++ /dev/null @@ -1,81 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of computers and servers and access - to them.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 48664505-7d22-44ee-87d2-4c8a5bdc3d14 -known_false_positives: None identified. -name: Reconnaissance and Access to Computers via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is collecting information about computers. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::ServerInfo/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is collecting information about computers. Operation is - performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ - mitre_attack_id: - - T1592 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml deleted file mode 100644 index 1637bfac4c..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules.yml +++ /dev/null @@ -1,98 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover and access operating system - elements, such as processes, services, registry locations, security packages and - files.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c1d33ad9-1727-4f9f-a474-4adbe4fed68a -known_false_positives: None identified. -name: Reconnaissance and Access to Operating System Elements via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and tapping into ongoing processes, - mounted drives or other operating system elements. Operation is performed at the - device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true - OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, - /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR - match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true - OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, - /(?i)Get-RegistryMountedDrive/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and tapping into ongoing processes, - mounted drives or other operating system elements. Operation is performed at the - device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1057 - - T1083 - - T1592.002 - - T1046 - - T1012 - - T1007 - - T1047 - - T1592 - - T1518 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml deleted file mode 100644 index cc69c9c467..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules.yml +++ /dev/null @@ -1,80 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery and access to services and processes.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 0243d37c-57c1-4182-bfd1-39b212255fc8 -known_false_positives: None identified. -name: Reconnaissance and Access to Processes and Services via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is listing processes and services. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 50 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is listing processes and services. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1007 - - T1046 - - T1057 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 50 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml deleted file mode 100644 index 4ea264cc5b..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_mimikatz_modules.yml +++ /dev/null @@ -1,85 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery and access to network shares.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c97b6eb9-1d8b-4017-bbbb-2af7fc17bc3f -known_false_positives: None identified. -name: Reconnaissance and Access to Shared Resources via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)net::share/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Lateral Movement - - Stage:Collection - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml deleted file mode 100644 index dd4633a38e..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_and_access_to_shared_resources_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules that discover and access network and distributed - file system shares.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 6b7ca431-6b1e-4b40-9589-21cb368e369e -known_false_positives: None identified. -name: Reconnaissance and Access to Shared Resources via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true - OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, - /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true - OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, - /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Lateral Movement - - Stage:Collection - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for and accessing network shares. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml deleted file mode 100644 index c79a306b71..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules.yml +++ /dev/null @@ -1,101 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules that discover opportunities for malicious - access and persistence. Some examples include access to admin accounts, weak access - control policies, landing paths for dropping malicious software or data to exfiltrate, - registry locations to land autorun parameters, task scheduling opportunities, as - well as services and system files that can be compromised.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 3d8bd7f3-1061-4ac7-9225-6764cc0684d7 -known_false_positives: None identified. -name: Reconnaissance of Access and Persistence Opportunities via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is searching for an entry point into the infrastructure, - such as local admin accounts, opportunities to hijack processes, unattended install - files, or modifiable access objects. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true - OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, - /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true - OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, - /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true - OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, - /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true - OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, - /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true - OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, - /(?i)Get-UnquotedService/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is searching for an entry point into the infrastructure, - such as local admin accounts, opportunities to hijack processes, unattended install - files, or modifiable access objects. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1053 - - T1068 - - T1078 - - T1543 - - T1547 - - T1574 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml deleted file mode 100644 index 4011dcfffe..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_of_connectivity_via_powersploit_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-06' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies access to PowerSploit modules for reconnaissance of connectivity.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 525d32fd-65dd-4732-9b72-3cfc7ddddbd2 -known_false_positives: None identified. -name: Reconnaissance of Connectivity via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is performing port scans or searching for various - connectivity details such as DNS data, proxies, or ongoing RDP connections. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true - OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, - /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true - OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, - /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true - OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true - ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is performing port scans or searching for various connectivity - details such as DNS data, proxies, or ongoing RDP connections. Operation is performed - at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1021 - - T1039 - - T1135 - - T1021.002 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml deleted file mode 100644 index cbfc35bd95..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_of_credential_stores_and_services_via_mimikatz_modules.yml +++ /dev/null @@ -1,91 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies reconnaissance of credential stores and use of CryptoAPI services by - Mimikatz modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 5facee5b-79e4-47ab-b0e6-c625acc0554f -known_false_positives: None identified. -name: Reconnaissance of Credential Stores and Services via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is searching for and accessing credential stores. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, - /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true - OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Credential Access - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is searching for and accessing credential stores. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1098 - - T1590.001 - - T1078 - - T1589.001 - - T1590 - - T1068 - - T1589 - - T1590.003 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 80 - risk_severity: high - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml deleted file mode 100644 index c100454874..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_of_defensive_tools_via_powersploit_modules.yml +++ /dev/null @@ -1,83 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules for assessment of presence of defensive tools.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 24b4e659-63a2-4e7b-89ac-87dd659c7110 -known_false_positives: None identified. -name: Reconnaissance of Defensive Tools via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is looking for presence of anti virus software. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Find-AVSignature/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 40 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is looking for presence of anti virus software. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1592.002 - - T1595.002 - - T1592 - - T1595 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 40 - risk_severity: medium - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml deleted file mode 100644 index a919f28981..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules.yml +++ /dev/null @@ -1,82 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of PowerSploit modules for assessment of privilege escalation opportunities.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: b9b4492c-2af8-449b-beb4-b1b78d963321 -known_false_positives: None identified. -name: Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is engaging its privilege escalation module. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Invoke-PrivescAudit/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - impact: 60 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is engaging its privilege escalation module. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 60 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml deleted file mode 100644 index 0232e39486..0000000000 --- a/dist/ssa/srs/ssa___reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules.yml +++ /dev/null @@ -1,90 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-05' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies use of Mimikatz modules for discovery of process or service hijacking - opportunities via Microsoft Detours compatibility. Microsoft Detours is an open - source library for intercepting, monitoring and instrumenting binary functions on - Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory - code for target functions. The Detours package also contains utilities to attach - arbitrary DLLs and data segments called payloads to any Win32 binary.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: fc5c1cbd-7494-4314-aad2-458d6fd4fada -known_false_positives: None identified. -name: Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -- https://en.wikipedia.org/wiki/Microsoft_Detours -risk_message: Mimikatz malware is looking for and invoking Microsoft Detours package - that enables spoofing of in-memory code. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)misc::detours/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Discovery Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Recon - - Stage:Command And Control - - Consequence:Loss Of Control - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is looking for and invoking Microsoft Detours package - that enables spoofing of in-memory code. Operation is performed at the device - $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1543 - - T1055 - - T1574 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - _time - - process - - dest_device_id - - dest_user_id - risk_score: 70 - risk_severity: low - security_domain: endpoint -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml b/dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml deleted file mode 100644 index f91f7f5062..0000000000 --- a/dist/ssa/srs/ssa___setting_credentials_via_dsinternals_modules.yml +++ /dev/null @@ -1,106 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via DSInternals modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: d5ef590f-9bde-49eb-9c63-2f5b62a65b9c -known_false_positives: None identified. -name: Setting Credentials via DSInternals modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/MichaelGrafnetter/DSInternals -risk_message: DSInternals malware is accessing, using or setting Active Directory - or Azure credentials and accounts. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, - "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), - "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true - OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true - OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, - /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true - OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Source:Cloud Data - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllDSInternalsModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: DSInternals malware is accessing, using or setting Active Directory or - Azure credentials and accounts. Operation is performed at the device $dest_device_id$, - by the account $dest_user_id$ via command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - process_name - - parent_process_name - - _time - - process_path - - dest_user_id - - process - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via DSInternals modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log - file_name: logAllDSInternalsModules.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_dsinternals_modules.yml - name: Setting Credentials via DSInternals modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml b/dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml deleted file mode 100644 index f2771dd531..0000000000 --- a/dist/ssa/srs/ssa___setting_credentials_via_mimikatz_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via Mimikatz modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: c8b84699-7652-4363-910f-efd1ca82f780 -known_false_positives: None identified. -name: Setting Credentials via Mimikatz modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/gentilkiwi/mimikatz -risk_message: Mimikatz malware is accessing, using or setting account credentials. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllMimikatzModules.log - impact: 80 - kill_chain_phases: - - Actions on Objectives - message: Mimikatz malware is accessing, using or setting account credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 80 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via Mimikatz modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log - file_name: logAllMimikatzModules.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_mimikatz_modules.yml - name: Setting Credentials via Mimikatz modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 diff --git a/dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml b/dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml deleted file mode 100644 index 2cfe008d54..0000000000 --- a/dist/ssa/srs/ssa___setting_credentials_via_powersploit_modules.yml +++ /dev/null @@ -1,96 +0,0 @@ -author: Stanislav Miskovic, Splunk -datamodel: -- Endpoint_Processes -date: '2020-11-03' -deprecated: true -description: 'WARNING, this detection has been marked deprecated by the Splunk Threat - Research team, this means that it will no longer be maintained or supported. If - you have any questions feel free to email us at: research@splunk.com. This detection - identifies illegal setting of credentials via PowerSploit modules.' -how_to_implement: You must be ingesting Windows Security logs from devices of interest, - including the event ID 4688 with enabled command line logging. -id: 07b2a501-f967-4ddc-9f56-2dce46dfce44 -known_false_positives: None identified. -name: Setting Credentials via PowerSploit modules -product: -- Splunk Behavioral Analytics -references: -- https://github.com/PowerShellMafia/PowerSploit -risk_message: PowerSploit malware is setting passwords on Active Directory accounts. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ -search: '| from read_ssa_enriched_events() - - | eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), - cmd_line=ucast(map_get(input_event, "process"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, - /(?i)Set-DomainUserPassword/)=true ) - - | eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)), body=create_map(["event_id", event_id, "cmd_line", cmd_line]) - | into write_ssa_detected_events();' -tags: - analytic_story: - - Windows Persistence Techniques - asset_type: Windows - cis20: - - CIS 16 - - CIS 20 - confidence: 100 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - - Consequence:Loss Of Control - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/account_manipulation/logAllPowerSploitModulesWithOldNames.log - impact: 90 - kill_chain_phases: - - Actions on Objectives - message: PowerSploit malware is setting passwords on Active Directory accounts. - Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ - via command $cmd_line$ - mitre_attack_id: - - T1068 - - T1078 - - T1098 - nist: - - PR.AC - - PR.IP - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - dest_device_id - - dest_user_id - - process - - _time - risk_score: 90 - risk_severity: high - security_domain: endpoint -test: - name: Setting Credentials via PowerSploit modules - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log - file_name: logAllPowerSploitModulesWithOldNames.log - source: WinEventLog:Security - description: Test illegal credential setting detections - file: endpoint/ssa___setting_credentials_via_powersploit_modules.yml - name: Setting Credentials via PowerSploit modules - pass_condition: '@count_gt(0)' -type: TTP -version: 1 From 17d7312bc63eea87afb9501685f3390cd5619c6e Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 10 Jan 2022 18:00:59 -0500 Subject: [PATCH 6/9] excluding experimental detections from the package --- bin/generate.py | 12 ++- .../endpoint/ssa___detect_kerberoasting.yml | 0 .../ssa___first_time_seen_cmd_line.yml | 0 ...are_parent_process_relationship_lolbas.yml | 0 .../endpoint/unusually_long_command_line.yml | 0 .../complex/ssa___detect_kerberoasting.yml | 94 ------------------- ..._first_time_seen_command_line_argument.yml | 89 ------------------ ...rare_parent-child_process_relationship.yml | 88 ----------------- ...ction_by_machine_learning_method_-_ssa.yml | 62 ------------ 9 files changed, 10 insertions(+), 335 deletions(-) rename detections/{ => experimental}/endpoint/ssa___detect_kerberoasting.yml (100%) rename detections/{ => experimental}/endpoint/ssa___first_time_seen_cmd_line.yml (100%) rename detections/{ => experimental}/endpoint/ssa___rare_parent_process_relationship_lolbas.yml (100%) rename detections/{ => experimental}/endpoint/unusually_long_command_line.yml (100%) delete mode 100644 dist/ssa/complex/ssa___detect_kerberoasting.yml delete mode 100644 dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml delete mode 100644 dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml delete mode 100644 dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml diff --git a/bin/generate.py b/bin/generate.py index 7080c1468b..5d836075d6 100644 --- a/bin/generate.py +++ b/bin/generate.py @@ -40,6 +40,13 @@ def process_deprecated(file,file_path): file['description'] = DESCRIPTION_ANNOTATION + file['description'] return file +def process_experimental(file,file_path): + DESCRIPTION_ANNOTATION = "WARNING, this is a experimental detection, Splunk Threat Research has not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is NOT supported. If you have any questions feel free to email us at: research@splunk.com. " + if 'experimental' in file_path: + file['experimental'] = True + file['experimental'] = DESCRIPTION_ANNOTATION + file['description'] + return file + def load_file(file_path): with open(file_path, 'r', encoding="utf-8") as stream: try: @@ -47,6 +54,7 @@ def load_file(file_path): # mark any files that have been deprecated file = process_deprecated(file,file_path) + file = process_experimental(file,file_path) except yaml.YAMLError as exc: print(exc) @@ -112,11 +120,11 @@ def generate_ssa_yaml(detections, TEMPLATE_PATH, OUTPUT_PATH): for d in detections: # skip deprecated - if 'deprecated' in d and d['deprecated']: + if ('deprecated' in d and d['deprecated']) or ('experimental' in d and d['experimental']): continue else: # check if the search contains "stats", "first_time_event", or "adaptive_threshold" which would make it a complex pipeline - pattern = re.compile('stats|first_time_event|adaptive_threshold') + pattern = re.compile('stats|first_time_event|adaptive_threshold|conditional_anomaly') if re.findall("stats|first_time_event|adaptive_threshold", d['search']): # it is a complex pipeline diff --git a/detections/endpoint/ssa___detect_kerberoasting.yml b/detections/experimental/endpoint/ssa___detect_kerberoasting.yml similarity index 100% rename from detections/endpoint/ssa___detect_kerberoasting.yml rename to detections/experimental/endpoint/ssa___detect_kerberoasting.yml diff --git a/detections/endpoint/ssa___first_time_seen_cmd_line.yml b/detections/experimental/endpoint/ssa___first_time_seen_cmd_line.yml similarity index 100% rename from detections/endpoint/ssa___first_time_seen_cmd_line.yml rename to detections/experimental/endpoint/ssa___first_time_seen_cmd_line.yml diff --git a/detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml b/detections/experimental/endpoint/ssa___rare_parent_process_relationship_lolbas.yml similarity index 100% rename from detections/endpoint/ssa___rare_parent_process_relationship_lolbas.yml rename to detections/experimental/endpoint/ssa___rare_parent_process_relationship_lolbas.yml diff --git a/detections/endpoint/unusually_long_command_line.yml b/detections/experimental/endpoint/unusually_long_command_line.yml similarity index 100% rename from detections/endpoint/unusually_long_command_line.yml rename to detections/experimental/endpoint/unusually_long_command_line.yml diff --git a/dist/ssa/complex/ssa___detect_kerberoasting.yml b/dist/ssa/complex/ssa___detect_kerberoasting.yml deleted file mode 100644 index 0d07185006..0000000000 --- a/dist/ssa/complex/ssa___detect_kerberoasting.yml +++ /dev/null @@ -1,94 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: -- Certificates -date: '2020-10-21' -description: This search detects a potential kerberoasting attack via service principal - name requests -how_to_implement: The test data is converted from Windows Security Event logs generated - from Attach Range simulation and used in SPL search and extended to SPL2 -id: dabdd6d7-3e10-42be-8711-4e124f7a3850 -known_false_positives: Older systems that support kerberos RC4 by default NetApp may - generate false positives -name: Detect Kerberoasting -product: -- Splunk Behavioral Analytics -references: -- Initial ESCU implementation by Jose Hernandez and Patrick Bareiss -risk_message: Kerberoasting malware is potentially applying stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via command - $cmd_line$ -search: ' | from read_ssa_enriched_events() | eval _time=map_get(input_event, "_time"), - EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, - "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), - ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, - "service_id"), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), - event_id=ucast(map_get(input_event, "event_id"), "string", null) | where EventCode="4769" - AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" | first_time_event - input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] - | where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID - | eval start_time=_time, end_time=_time | eval body=create_map(["event_id", event_id, - "EventCode", EventCode, "ServiceName", ServiceName, "TicketOptions", TicketOptions, - "TicketEncryptionType", TicketEncryptionType]), entities = mvappend(ucast(map_get(input_event, - "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), - "string", null)) | select start_time, end_time, entities, body | into write_ssa_detected_events();' -tags: - analytic_story: - - Credential Dumping - cis20: - - CIS 8 - - CIS 16 - confidence: 20 - context: - - Source:AD - - Source:Endpoint - - Stage:Credential Access - impact: 70 - kill_chain_phases: - - Actions on Objectives - message: Kerberoasting malware is potentially applying stolen credentials. Operation - is performed at the device $dest_device_id$, by the account $dest_user_id$ via - command $cmd_line$ - mitre_attack_id: - - T1558.003 - - T1558 - nist: - - DE.CM - observable: - - name: dest_user_id - role: - - Actor - type: User - - name: dest_device_id - role: - - Victim - type: Hostname - - name: cmd_line - role: - - Others - type: processname - product: - - Splunk Behavioral Analytics - required_fields: - - service_name - - _time - - event_code - - ticket_encryption_type - - service_id - - ticket_options - risk_score: 14 - risk_severity: medium - security_domain: endpoint -test: - name: Detect Kerberoasting - SSA Unit test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test detection of kerberoasting - file: endpoint/ssa___detect_kerberoasting.yml - name: Detect kerberoasting - pass_condition: '@count_eq(0)' -type: TTP -version: 2 diff --git a/dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml b/dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml deleted file mode 100644 index 5bed7361d2..0000000000 --- a/dist/ssa/complex/ssa___first_time_seen_command_line_argument.yml +++ /dev/null @@ -1,89 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: This search looks for command-line arguments that use a `/c` parameter - to execute a command that has not previously been seen. This is an implementation - on SPL2 of the rule `First time seen command line argument` by @bpatel. 'The following - analytic identifies first time seen command-line arguments on a single endpoint. - The analytic looks for arguments instantiated by `cmd.exe /c` and the associated - command-line. Adversaries automate or spawn multiple processes using this method, - this analytic may assist with identifying the first time it's been found on this - endpoint.' -how_to_implement: To successfully implement this search, you need to be ingesting - logs with the process name, parent process, and command-line executions from your - endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the - Sysmon TA. -id: fc0edc95-ff2b-48b0-9f6f-63da3789fd23 -known_false_positives: Legitimate programs use command-line arguments to execute. - Verify the command-line arguments to check what command/program is being executed. - Filtering will be needed. -name: First time seen command line argument -product: -- Splunk Behavioral Analytics -references: [] -risk_message: A process $process_name$ ha been identified in the environment with - a command-line $cmd_line$ not previously seen before on host $dest_device_id$ -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), - "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", - null), process_name=ucast(map_get(input_event, "process_name"), "string", null), - cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), - cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, - "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, - "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" - */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s|$)+)/, "\\PATH"), - /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, - /\d+/, "N"), event_id=ucast(map_get(input_event, "event_id"), "string", null) | - where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* - \/[cC] .*/)=true | select process_name, cmd_line, cmd_line_norm, timestamp, dest_device_id, - dest_user_id | first_time_event input_columns=["cmd_line_norm"] | where first_time_cmd_line_norm - | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, - dest_user_id), body=create_map(["event_id", event_id, "cmd_line", cmd_line, "process_name", - process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 3 - - CIS 8 - confidence: 60 - context: - - source:endpoint - - stage: Defense Evasion - impact: 50 - kill_chain_phases: - - Command and Control - - Actions on Objectives - message: A process $process_name$ ha been identified in the environment with a command-line - $cmd_line$ not previously seen before on host $dest_device_id$ - mitre_attack_id: - - T1059 - - T1202 - nist: - - PR.PT - - DE.CM - - PR.IP - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - - cmd_line - risk_score: 30 - risk_severity: medium - security_domain: endpoint -type: Anomaly -version: 4 diff --git a/dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml b/dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml deleted file mode 100644 index 4f0ce19970..0000000000 --- a/dist/ssa/complex/ssa___rare_parent-child_process_relationship.yml +++ /dev/null @@ -1,88 +0,0 @@ -author: Peter Gael, Splunk; Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2021-11-30' -description: An attacker may use LOLBAS tools spawned from vulnerable applications - not typically used by system administrators. This analytic leverages the Splunk - Streaming ML DSP plugin to find rare parent/child relationships. The list of application - has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -how_to_implement: Collect endpoint data such as sysmon or 4688 events. -id: cf090c78-bcc6-11eb-8529-0242ac130003 -known_false_positives: Some custom tools used by administrators could be used rarely - to launch remotely applications. This might trigger false positives at the beginning - when it has not collected yet enough data to construct the baseline. -name: Rare Parent-Child Process Relationship -product: -- Splunk Behavioral Analytics -references: -- https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries -search: '| from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval parent_process=lower(ucast(map_get(input_event, - "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, - "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", - null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, - "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), - "string", null), event_id=ucast(map_get(input_event, "event_id"), "string", null) - | where parent_process_name!=null | select parent_process_name, process_name, cmd_line, - timestamp, dest_device_id, dest_user_id | conditional_anomaly conditional="parent_process_name" - target="process_name" | where (process_name="powershell.exe" OR process_name="regsvcs.exe" - OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" - OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" - OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" - OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" - OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" - OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" - OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" - OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" - OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" - OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" - OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" - OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" - OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" - OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" - OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" - OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" - OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" - OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" - OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" - OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" - OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR - process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" - OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" - OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" - OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") - | eval input = (-1)*log(output) | adaptive_threshold algorithm="gaussian" threshold=0.001 - window=604800000L | where label AND input > mean | eval start_time = timestamp, - end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = - create_map(["process_name", process_name, "parent_process_name", parent_process_name, - "input", input, "mean", mean, "variance", variance, "output", output, "cmd_line", - cmd_line]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - kill_chain_phases: - - Exploitation - mitre_attack_id: - - T1203 - - T1059 - - T1053 - - T1072 - nist: - - PR.PT - - DE.CM - product: - - Splunk Behavioral Analytics - required_fields: - - process - - process_name - - parent_process_name - - _time - - dest_device_id - - dest_user_id - - cmd_line - risk_severity: low - security_domain: endpoint -type: Anomaly -version: 2 diff --git a/dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml b/dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml deleted file mode 100644 index c1f2707376..0000000000 --- a/dist/ssa/srs/ssa___phishing_email_detection_by_machine_learning_method_-_ssa.yml +++ /dev/null @@ -1,62 +0,0 @@ -author: Xiao Lin, Splunk -datamodel: [] -date: '2020-08-25' -description: Malicious mails can conduct phishing that induces readers to open attachment, - click links or trigger third party service. This detect uses Natural Language Processing - (NLP) approach to analyze an email message's content (Sender, Subject and Body) - and judge whether it is a phishing email. The detection adopts a deep learning (neural - network) model that employs character level embeddings plus LSTM layers to perform - classification. The model is pre-trained and then published as ONNX format. Current - sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json - User are expected to re-train the model by combining with their own training data - for better accuracy using the provided model file (SMLE notebook). DSP pipeline - then processes the email message and passes it as an event to Apply ML Models function, - which returns the probability of a phishing email. Current implementation assumes - the email is fed to DSP in JSON format contains at least email's sender, subject - and its message body, including reply content, if any. -how_to_implement: Events are fed to DSP contains at least email's sender, subject - and its message body. -id: 4b237388-dfa1-41a6-91d4-4de2d598376f -known_false_positives: Because of imbalance of anomaly data in training, the model - will less likely report false positive. Instead, the model is more prone to false - negative. Current best recall score is ~85% -name: Phishing Email Detection by Machine Learning Method - SSA -product: -- Splunk Behavioral Analytics -references: [] -search: '| from read_ssa_enriched_events() | eval eventLine=concat(ucast(map_get(input_event, - "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " - "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), - _time=map_get(input_event, "_time") | where eventLine IS NOT NULL | eval mapC={" - ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, - ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, - "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, - ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, - "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, - "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, - "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, - "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": - 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": - 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": - 119, "x": 120, "y": 121, "z": 122, "{": 123, "|": 124, "}": 125, "~": 126}, ml_in - = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, - 1)), "float") ) | apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" - path="s3://smle-experiments/models/phishing_email" | eval probability = mvindex(ml_out, - 0) | where probability > 0.5 | eval start_time=_time, end_time=_time, entities="TBD", - body="TBD" | select probability, body, entities, start_time, end_time | into write_ssa_detected_events();' -tags: - cis20: - - CIS 8 - kill_chain_phases: - - Actions on Objectives - mitre_attack_id: - - T1566 - nist: - - PR.PT - - DE.CM - product: - - Splunk Behavioral Analytics - risk_severity: low - security_domain: mail server -type: Anomaly -version: 1 From ede5fd35af31f29d0d2346136d3018cd7c5aa236 Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 10 Jan 2022 18:06:45 -0500 Subject: [PATCH 7/9] moving ssa detection deprecated --- .../ssa___unusual_lolbas_in_short_period_of_time.yml | 0 1 file changed, 0 insertions(+), 0 deletions(-) rename detections/{endpoint => deprecated}/ssa___unusual_lolbas_in_short_period_of_time.yml (100%) diff --git a/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml b/detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml similarity index 100% rename from detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml rename to detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml From 2d3acc2019dec56d00ae5adb48d8841325c0a1ea Mon Sep 17 00:00:00 2001 From: d1vious Date: Mon, 10 Jan 2022 18:11:10 -0500 Subject: [PATCH 8/9] moved detections to deprecated --- .../ssa___unusually_long_command_line.yml | 0 ...unusual_lolbas_in_short_period_of_time.yml | 0 .../ssa___unusually_long_command_line.yml | 87 ------------------- 3 files changed, 87 deletions(-) rename detections/{endpoint => deprecated}/ssa___unusually_long_command_line.yml (100%) rename detections/{deprecated => endpoint}/ssa___unusual_lolbas_in_short_period_of_time.yml (100%) delete mode 100644 dist/ssa/complex/ssa___unusually_long_command_line.yml diff --git a/detections/endpoint/ssa___unusually_long_command_line.yml b/detections/deprecated/ssa___unusually_long_command_line.yml similarity index 100% rename from detections/endpoint/ssa___unusually_long_command_line.yml rename to detections/deprecated/ssa___unusually_long_command_line.yml diff --git a/detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml b/detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml similarity index 100% rename from detections/deprecated/ssa___unusual_lolbas_in_short_period_of_time.yml rename to detections/endpoint/ssa___unusual_lolbas_in_short_period_of_time.yml diff --git a/dist/ssa/complex/ssa___unusually_long_command_line.yml b/dist/ssa/complex/ssa___unusually_long_command_line.yml deleted file mode 100644 index 7431805fa7..0000000000 --- a/dist/ssa/complex/ssa___unusually_long_command_line.yml +++ /dev/null @@ -1,87 +0,0 @@ -author: Ignacio Bermudez Corrales, Splunk -datamodel: -- Endpoint_Processes -date: '2020-10-06' -description: Command lines that are extremely long may be indicative of malicious - activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin - to help identify command lines with lengths that are unusual for a given user. This - detection is inspired on Unusually Long Command Line authored by Rico Valdez. -how_to_implement: You must be ingesting sysmon endpoint data that monitors command - lines. -id: 58f43aba-1775-445e-b19c-be2b87d83ae3 -known_false_positives: This detection may flag suspiciously long command lines when - there is not sufficient evidence (samples) for a given process that this detection - is tracking; or when there is high variability in the length of the command line - for the tracked process. Also, some legitimate applications may use long command - lines. Such is the case of Ansible, that encodes Powershell scripts using long base64. - Attackers may use this technique to obfuscate their payloads. -name: Unusually Long Command Line -product: -- Splunk Behavioral Analytics -references: [] -risk_message: A process $process_name$ with a long commandline $cmd_line$ executed - in host $dest_device_id$ -search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(map_get(input_event, - "_time"), "string", null)) | eval cmd_line=ucast(map_get(input_event, "process"), - "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", - null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), - process_name=ucast(map_get(input_event, "process_name"), "string", null), event_id=ucast(map_get(input_event, - "event_id"), "string", null) | where cmd_line!=null and dest_user_id!=null | eval - cmd_line_norm=replace(cast(cmd_line, "string"), /\s(--?\w+)|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, - /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, - ""))) | select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, - input | adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 - | where label AND quantile>0.99 | first_time_event input_columns=["dest_device_id", - "cmd_line"] | where first_time_dest_device_id_cmd_line | eval start_time = timestamp, - end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body=create_map(["event_id", - event_id, "cmd_line", cmd_line, "process_name", process_name]) | into write_ssa_detected_events();' -tags: - analytic_story: - - Unusual Processes - cis20: - - CIS 8 - confidence: 40 - context: - - source:endpoint - - stage: Defense Evasion - impact: 30 - kill_chain_phases: - - Actions on Objectives - message: A process $process_name$ with a long commandline $cmd_line$ executed in - host $dest_device_id$ - nist: - - PR.PT - - DE.CM - observable: - - name: dest_device_id - role: - - Victim - type: Hostname - - name: dest_user_id - role: - - Victim - type: user - product: - - Splunk Behavioral Analytics - required_fields: - - process_name - - _time - - dest_device_id - - dest_user_id - - process - risk_score: 12 - risk_severity: medium - security_domain: endpoint -test: - name: Unusually Long Command Line - SSA Unit Test - tests: - - attack_data: - - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/unusally_cmd_line/windows-security.log - file_name: windows-security.log - source: WinEventLog:Security - description: Test unusually long command lines - file: endpoint/ssa___unusually_long_command_line.yml - name: Unusually Long Command Line - pass_condition: '@count_gt(0)' -type: Anomaly -version: 1 From bac993ba40c6283b70a18e670420ee4bcc361e2d Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Thu, 13 Jan 2022 10:14:14 -0800 Subject: [PATCH 9/9] delete orphaned file --- tests/endpoint/unusually_long_command_line.test.yml | 12 ------------ 1 file changed, 12 deletions(-) delete mode 100644 tests/endpoint/unusually_long_command_line.test.yml diff --git a/tests/endpoint/unusually_long_command_line.test.yml b/tests/endpoint/unusually_long_command_line.test.yml deleted file mode 100644 index 475d227b74..0000000000 --- a/tests/endpoint/unusually_long_command_line.test.yml +++ /dev/null @@ -1,12 +0,0 @@ -name: Unusually Long Command Line Unit Test -tests: -- name: Unusually Long Command Line - file: endpoint/unusually_long_command_line.yml - pass_condition: '| stats count | where count > 0' - earliest_time: '-24h' - latest_time: 'now' - attack_data: - - file_name: windows-sysmon.log - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/atomic_red_team/windows-sysmon.log - source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational - sourcetype: xmlwineventlog