diff --git a/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml b/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml index 5265bd86ff..9f7ff27e72 100644 --- a/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml +++ b/bin/docker_detection_tester/ansible/roles/attack_replay/tasks/main.yml @@ -20,4 +20,4 @@ sourcetype: "{{ sourcetype }}" rename-source: "{{ source }}" index: "{{ index }}" - status_code: 201 \ No newline at end of file + status_code: 201 diff --git a/bin/docker_detection_tester/modules/validate_args.py b/bin/docker_detection_tester/modules/validate_args.py index a5ff54e475..9ad7cc7942 100644 --- a/bin/docker_detection_tester/modules/validate_args.py +++ b/bin/docker_detection_tester/modules/validate_args.py @@ -142,9 +142,14 @@ setup_schema = { "URL_TOOLBOX": { "app_number": 2734, "app_version": "1.9.2", - "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz", - }, - "SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": { + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz" + }, + "SPLUNK_TA_FIX_WINDOWS":{ + "app_number": 9999, + "app_version": "1.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz" + }, + "SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": { "app_number": 3110, "app_version": "4.5.2", "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_452.tgz", diff --git a/bin/docker_detection_tester/test_config_github_actions.json b/bin/docker_detection_tester/test_config_github_actions.json index dac273e5e3..898ca9183f 100644 --- a/bin/docker_detection_tester/test_config_github_actions.json +++ b/bin/docker_detection_tester/test_config_github_actions.json @@ -1,9 +1,109 @@ { "apps": { - "ADD_ON_FOR_LINUX_SYSMON": { - "app_number": 6176, - "app_version": "1.0.4", - "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz" + "Splunk Add-on for CrowdStrike FDR": { + "app_number": 5579, + "app_version": "1.2.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_120.tgz" + }, + "ADD_ON_FOR_LINUX_SYSMON": { + "app_number": 6176, + "app_version": "1.0.4", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz" + }, + "PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": { + "app_number": 2757, + "app_version": "7.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/palo-alto-networks-add-on-for-splunk_710.tgz" + }, + "PYTHON_FOR_SCIENTIFIC_COMPUTING_FOR_LINUX_64_BIT": { + "app_number": 2882, + "app_version": "3.0.2", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/python-for-scientific-computing-for-linux-64-bit_302.tgz" + }, + "SPLUNK_ADD_ON_FOR_AMAZON_KINESIS_FIREHOSE": { + "app_number": 3719, + "app_version": "1.3.2", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-amazon-kinesis-firehose_132.tgz" + }, + "SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365": { + "app_number": 4055, + "app_version": "4.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_400.tgz" + }, + "SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS": { + "app_number": 742, + "app_version": "8.5.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_850.tgz" + }, + "SPLUNK_ADD_ON_FOR_NGINX": { + "app_number": 3258, + "app_version": "3.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-nginx_310.tgz" + }, + "SPLUNK_ADD_ON_FOR_STREAM_FORWARDERS": { + "app_number": 5238, + "app_version": "8.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-forwarders_810.tgz" + }, + "SPLUNK_ADD_ON_FOR_STREAM_WIRE_DATA": { + "app_number": 5234, + "app_version": "8.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-wire-data_810.tgz" + }, + "SPLUNK_ADD_ON_FOR_SYSMON": { + "app_number": 5709, + "app_version": "3.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-sysmon_300.tgz" + }, + "SPLUNK_ADD_ON_FOR_UNIX_AND_LINUX": { + "app_number": 833, + "app_version": "8.6.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_860.tgz" + }, + "SPLUNK_APP_FOR_STREAM": { + "app_number": 1809, + "app_version": "8.1.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-app-for-stream_810.tgz" + }, + "SPLUNK_TA_FIX_WINDOWS":{ + "app_number": 9999, + "app_version": "1.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz" + }, + "SPLUNK_COMMON_INFORMATION_MODEL": { + "app_number": 1621, + "app_version": "5.0.1", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_501.tgz" + }, + "SPLUNK_ES_CONTENT_UPDATE": { + "app_number": 3449, + "app_version": null, + "local_path": null + }, + "SPLUNK_MACHINE_LEARNING_TOOLKIT": { + "app_number": 2890, + "app_version": "5.3.1", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-machine-learning-toolkit_531.tgz" + }, + "SPLUNK_TA_FOR_ZEEK": { + "app_number": 5466, + "app_version": "1.0.5", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/ta-for-zeek_105.tgz" + }, + "URL_TOOLBOX": { + "app_number": 2734, + "app_version": "1.9.2", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz" + }, + "SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM": { + "app_number": 3088, + "app_version": "4.0.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-cloud-platform_400.tgz" + }, + "SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE": { + "app_number": 3110, + "app_version": "2.3.0", + "http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-workspace_230.tgz" }, "PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": { "app_number": 2757, diff --git a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml index 4dd30a3070..30c1179d88 100644 --- a/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml +++ b/detections/cloud/azure_ad_multiple_users_failing_to_authenticate_from_ip.yml @@ -49,6 +49,7 @@ tags: - T1586.003 - T1110 - T1110.003 + - T1110.004 nist: - DE.CM observable: diff --git a/detections/cloud/gcp_multi_factor_authentication_disabled.yml b/detections/cloud/gcp_multi_factor_authentication_disabled.yml index e35f411f80..c6585220d1 100644 --- a/detections/cloud/gcp_multi_factor_authentication_disabled.yml +++ b/detections/cloud/gcp_multi_factor_authentication_disabled.yml @@ -42,6 +42,7 @@ tags: - T1586 - T1586.003 - T1556 + - T1556.006 nist: - DE.CM observable: diff --git a/detections/endpoint/disabling_windows_local_security_authority_defences_via_registry.yml b/detections/endpoint/disabling_windows_local_security_authority_defences_via_registry.yml new file mode 100644 index 0000000000..f58816a812 --- /dev/null +++ b/detections/endpoint/disabling_windows_local_security_authority_defences_via_registry.yml @@ -0,0 +1,76 @@ +name: Disabling Windows Local Security Authority Defences via Registry +id: 45cd08f8-a2c9-4f4e-baab-e1a0c624b0ab +version: 1 +date: '2022-09-09' +author: Dean Luxton +type: TTP +datamodel: +- Endpoint +description: This detection looks for the deletion of registry keys which disable LSA protection and MS Defender Device Guard. +search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Endpoint.Registry + where Registry.registry_path IN ("*\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\LsaCfgFlags", + "*\\SOFTWARE\\Policies\\Microsoft\\Windows\\DeviceGuard\\*", "*\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\RunAsPPL") + Registry.action IN (deleted, unknown) by Registry.action Registry.registry_path + Registry.process_guid + | `drop_dm_object_name(Registry)` + | join type=outer process_guid [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by Processes.user Processes.process_name Processes.process + Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid + | `drop_dm_object_name(Processes)`] + | table _time action dest user parent_process_name parent_process process_name process + process_guid registry_path | `disabling_windows_local_security_authority_defences_via_registry_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Potential to be triggered by an administrator disabling protections for troubleshooting purposes. +references: +- https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/configuring-additional-lsa-protection +- https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-manage +tags: + analytic_story: + - Windows Defence Evasion Tactics + - Windows Registry Abuse + asset_type: Endpoint + cis20: + - CIS 5 + - CIS 6 + - CIS 16 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_lsa_protection/windows-sysmon.log + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_credential_guard/windows-sysmon.log + impact: 60 + kill_chain_phases: + - Actions on Objectives + message: An attempt to disable Windows LSA defences was detected on $dest$. The reg key $registry_path$ was deleted by $user$. + mitre_attack_id: + - T1556 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.action + - Registry.registry_path + - Registry.dest + - Registry.user + risk_score: 60 + security_domain: endpoint diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 7cf8f71de9..888d484319 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -57,6 +57,7 @@ tags: - Qakbot - Chaos Ransomware - AsyncRAT + - Sneaky Active Directory Persistence Tricks asset_type: Endpoint cis20: - CIS 8 diff --git a/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml new file mode 100644 index 0000000000..9218bbdecd --- /dev/null +++ b/detections/endpoint/windows_ad_adminsdholder_acl_modified.yml @@ -0,0 +1,76 @@ +name: Windows AD AdminSDHolder ACL Modified +id: 00d877c3-7b7b-443d-9562-6b231e2abab9 +version: 1 +date: '2022-11-15' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic identifies the modification of the Access Control List for the AdminSDHolder object within a Windows domain. Specifically, the + detection triggers on the addition of a new rule to the existing ACL. AdminSDHolder is an object located in the System Partition in Active Directory and is used as a + security template for objects that are members of certain privileged groups. Objects in these groups are enumerated and any objects with security descriptors that dont + match the AdminSDHolder ACL are flagged for updating. The Security Descriptor propagator (SDProp) process runs every 60 minutes on the PDC Emulator and re-stamps the object + Access Control List (ACL) with the security permissions set on the AdminSDHolder. An adversary who has obtained privileged access to a Windows Domain may modify the AdminSDHolder + ACL to establish persistence and allow an unprivileged user to take control of a domain. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=nTSecurityDescriptor OperationType="%%14674" ObjectDN="CN=AdminSDHolder,CN=System*" + | rex field=AttributeValue max_match=10000 "A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;(?PS-1-[0-59]-\d{2}-\d{8,10}-\d{8,10}-\d{8,10}-[1-9]\d{3})\)" + | stats values(added_user_sid) by _time, Computer, SubjectUserName, ObjectDN + | `windows_ad_adminsdholder_acl_modified_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for the AdminSDHolder object in order to log modifications. +known_false_positives: Adding new users or groups to the AdminSDHolder ACL is not usual. Filter as needed +references: +- https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-c--protected-accounts-and-groups-in-active-directory +- https://social.technet.microsoft.com/wiki/contents/articles/22331.adminsdholder-protected-groups-and-security-descriptor-propagator.aspx +- https://adsecurity.org/?p=1906 +- https://pentestlab.blog/2022/01/04/domain-persistence-adminsdholder/ +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 +- https://learn.microsoft.com/en-us/windows/win32/secauthz/access-control-lists +- https://medium.com/@cryps1s/detecting-windows-endpoint-compromise-with-sacls-cd748e10950 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/adminsdholder_modified/windows-security.log + impact: 80 + kill_chain_phases: + - Installation + - Actions on Objectives + message: The AdminSDHolder domain object has been modified on $Computer$ by $SubjectUserName$ + mitre_attack_id: + - T1546 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: Computer + type: Endpoint + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AttributeLDAPDisplayName + - OperationType + - ObjectDN + - Computer + - SubjectUserName + - AttributeValue + risk_score: 56 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml new file mode 100644 index 0000000000..e88f948647 --- /dev/null +++ b/detections/endpoint/windows_ad_cross_domain_sid_history_addition.yml @@ -0,0 +1,75 @@ +name: Windows AD Cross Domain SID History Addition +id: 41bbb371-28ba-439c-bb5c-d9930c28365d +version: 1 +date: '2022-11-17' +author: Dean Luxton +type: TTP +datamodel: [] +description: The following analytic looks for changes to the sIDHistory AD attribute of user or computer objects within different domains. + The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access + continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries for inter-domain privilege escalation and persistence. +search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory IN ("%%1793", -) + | rex field=SidHistory "(^%{|^)(?P.*)(\-|\\\)" + | rex field=TargetSid "^(?P.*)(\-|\\\)" + | where SidHistoryMatch!=TargetSidmatch AND SidHistoryMatch!=TargetDomainName + | rename TargetSid as userSid + | table _time action status host user userSid SidHistory Logon_ID src_user + | `windows_ad_cross_domain_sid_history_addition_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcodes + `4738` and `4742`. The Advanced Security Audit policy settings + `Audit User Account Management` and `Audit Computer Account Management` + within `Account Management` all need to be enabled. +known_false_positives: Domain mergers and migrations may generate large volumes of false positives for this analytic. +references: +- https://adsecurity.org/?p=1772 +- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN +- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + - CIS 16 + confidence: 80 + context: + - Source:AD + - Stage:Persistence + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Active Directory SID History Attribute was added to $user$ by $src_user$ + mitre_attack_id: + - T1134.005 + - T1134 + nist: + - DE.CM + observable: + - name: src_user + type: User + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - SidHistory + - TargetSid + - TargetDomainName + - user + - src_user + - Logon_ID + risk_score: 80 + security_domain: endpoint + diff --git a/detections/endpoint/windows_ad_domain_controller_promotion.yml b/detections/endpoint/windows_ad_domain_controller_promotion.yml new file mode 100644 index 0000000000..dda3b1e0c4 --- /dev/null +++ b/detections/endpoint/windows_ad_domain_controller_promotion.yml @@ -0,0 +1,69 @@ +name: Windows AD Domain Controller Promotion +id: e633a0ef-2a6e-4ed7-b925-5ff999e5d1f0 +version: 1 +date: '2023-01-26' +author: Dean Luxton +type: TTP +datamodel: [] +description: This analytic identifies a genuine DC promotion event. Identifying when a computer assigns itself the + necessary SPNs to function as a domain controller. Note these events are triggered on the existing domain controllers, not the newly + joined domain controller. This detection will serve to identify rogue DCs added to the network. There are 2x detections within this analytic story + which identify DCShadow attacks, if you do not currently possess the logging for these detections, remove the where clause within this + detection to identify DCShadow activity. +search: "`wineventlog_security` EventCode=4742 ServicePrincipalNames IN (\"*E3514235-4B06-11D1-AB04-00C04FC2DCD2/*\"\ + , \"*GC/*\") \n| stats min(_time) as _time latest(ServicePrincipalNames) as ServicePrincipalNames,\ + \ values(signature) as signature, values(src_user) as src_user, values(user) as\ + \ user by Logon_ID, dvc\n| where src_user=user\n| rename Logon_ID as TargetLogonId,\ + \ user as dest\n| appendpipe [| map search=\"search `wineventlog_security` EventCode=4624\ + \ TargetLogonId=$TargetLogonId$\" | fields - dest, dvc, signature]\n| stats min(_time)\ + \ as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain,\ + \ values(user) as user, values(status) as status, values(src_category) as src_category,\ + \ values(src_ip) as src_ip values(ServicePrincipalNames) as ServicePrincipalNames\ + \ values(signature) as signature values(dest) as dest values(dvc) as dvc by TargetLogonId\n\ + | eval dest=trim(dest,\"$\") | `windows_ad_domain_controller_promotion_filter`" +how_to_implement: To successfully implement this search, you need to be ingesting eventcode + `4742`. The Advanced Security Audit policy setting `Audit Computer Account Management` + within `Account Management` needs to be enabled. +known_false_positives: None. +references: +- https://attack.mitre.org/techniques/T1207/ +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/dc_promo/windows-security-xml.log + impact: 80 + kill_chain_phases: + - Actions on Objectives + message: AD Domain Controller Promotion Event Detected for $dest$ + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ServicePrincipalNames + - src_user + - user + - Logon_ID + - dvc + risk_score: 80 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_dsrm_account_changes.yml b/detections/endpoint/windows_ad_dsrm_account_changes.yml new file mode 100644 index 0000000000..934fe94634 --- /dev/null +++ b/detections/endpoint/windows_ad_dsrm_account_changes.yml @@ -0,0 +1,75 @@ +name: Windows AD DSRM Account Changes +id: 08cb291e-ea77-48e8-a95a-0799319bf056 +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: +- Endpoint +description: Aside from being used to promote genuine domain controllers, the DSRM (Directory Services Restore Mode) + account can be used to persist within a Domain. A DC can be configured to allow the DSRM account to logon & be + used in the same way as a local administrator account. This detection is looking for alterations to the behaviour + of the account via registry. +search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Endpoint.Registry + where Registry.registry_path= "*\\System\\CurrentControlSet\\Control\\Lsa\\DSRMAdminLogonBehavior" + Registry.registry_value_data IN ("*1","*2") by Registry.action Registry.registry_path + Registry.registry_value_data Registry.registry_value_type Registry.process_guid + | `drop_dm_object_name(Registry)` + | join type=outer process_guid [| tstats `security_content_summariesonly` count + FROM datamodel=Endpoint.Processes by Processes.user Processes.process_name Processes.process + Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid + | `drop_dm_object_name(Processes)`] + | table _time action dest user parent_process_name parent_process process_name process + process_guid registry_path registry_value_data registry_value_type | `windows_ad_dsrm_account_changes_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Disaster recovery events. +references: +- https://adsecurity.org/?p=1714 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Windows Registry Abuse + - Windows Persistence Techniques + asset_type: Endpoint + cis20: + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: DSRM Account Changes Initiated on $dest$ by $user$ + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.registry_value_data + - Registry.registry_path + - Registry.dest + - Registry.user + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_dsrm_password_reset.yml b/detections/endpoint/windows_ad_dsrm_password_reset.yml new file mode 100644 index 0000000000..3664351cc2 --- /dev/null +++ b/detections/endpoint/windows_ad_dsrm_password_reset.yml @@ -0,0 +1,65 @@ +name: Windows AD DSRM Password Reset +id: d1ab841c-36a6-46cf-b50f-b2b04b31182a +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: +- Change +description: Aside from being used to promote genuine domain controllers, the DSRM (Directory Services Restore Mode) + account can be used to persist within a Domain. A DC can be configured to allow the DSRM account to logon & be + used in the same way as a local administrator account. This detection is looking for any password reset attempts against that account. +search: '| tstats `security_content_summariesonly` min(_time) as _time from datamodel=Change + where All_Changes.result_id="4794" AND All_Changes.result="An attempt was made to + set the Directory Services Restore Mode administrator password" by All_Changes.action, + All_Changes.dest, All_Changes.src, All_Changes.user + | `drop_dm_object_name(All_Changes)` | `windows_ad_dsrm_password_reset_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode + `4794` and have the Advanced Security Audit policy + `Audit User Account Management` within `Account Management` enabled. +known_false_positives: Resetting the DSRM password for legitamate reasons, i.e. forgot the password. Disaster recovery. Deploying AD backdoor deliberately. +references: +- https://adsecurity.org/?p=1714 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: DSRM Account Password was reset on $dest$ by $user$ + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - All_Changes.result_id + - All_Changes.result + - All_Changes.action + - All_Changes.dest + - All_Changes.src + - All_Changes.user + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml new file mode 100644 index 0000000000..928ba49bab --- /dev/null +++ b/detections/endpoint/windows_ad_replication_request_initiated_by_user_account.yml @@ -0,0 +1,84 @@ +name: Windows AD Replication Request Initiated by User Account +id: 51307514-1236-49f6-8686-d46d93cc2821 +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: [] +description: This alert was written to detect activity associated with the DCSync attack. + When a domain controller receives a replication request, the user account permissions are validated, however no checks are performed to validate the request was initiated by a Domain Controller. + Once an attacker gains control of an account with the necessary privileges, they can request password hashes for any or all users within the domain. + This alert detects when a user account creates a handle to domainDNS with the necessary replication permissions. +search: '`wineventlog_security` EventCode=4662 ObjectType IN ("%{19195a5b-6da0-11d0-afd3-00c04fd930c9}", "domainDNS") AND Properties IN ("*Replicating Directory Changes All*", "*{1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}*", "*{9923a32a-3607-11d2-b9be-0000f87a36b2}*","*{1131f6ac-9c07-11d1-f79f-00c04fc2dcd2}*") AND AccessMask="0x100" AND NOT (SubjectUserSid="NT AUT*" OR SubjectUserSid="S-1-5-18" OR SubjectDomainName="Window Manager" OR SubjectUserName="*$") + | stats min(_time) as _time, count by SubjectDomainName, SubjectUserName, Computer, Logon_ID, ObjectName, ObjectServer, ObjectType, OperationType, status + | rename SubjectDomainName as Target_Domain, SubjectUserName as user, Logon_ID as TargetLogonId, _time as attack_time + | appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"] + | table attack_time, AuthenticationPackageName, LogonProcessName, LogonType, TargetUserSid, Target_Domain, user, Computer, TargetLogonId, status, src_ip, src_category, ObjectName, ObjectServer, ObjectType, OperationType + | stats min(attack_time) as _time values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) as status, values(src_category) as src_category, values(src_ip) as src_ip by TargetLogonId + | `windows_ad_replication_request_initiated_by_user_account_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode `4662`. + The Advanced Security Audit policy settings `Audit Directory Services Access` + within `DS Access` needs to be enabled, as well as the following SACLs applied to the domain root + and all descendant objects. The principals `everybody`, `Domain Computers`, and `Domain Controllers` + auditing the permissions `Replicating Directory Changes`, `Replicating Directory Changes All`, and + `Replicating Directory Changes In Filtered Set` +known_false_positives: Azure AD Connect syncing operations. +references: +- https://adsecurity.org/?p=1729 +- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer +- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Credential Dumping + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Source:AD + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Windows Active Directory Replication Request Initiated by User Account $user$ at $src_ip$ + mitre_attack_id: + - T1003.006 + - T1003 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_ip + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectType + - Properties + - AccessMask + - SubjectDomainName + - SubjectUserName + - SubjectUserSid + - Computer + - Logon_ID + - ObjectName + - ObjectServer + - ObjectType + - OperationType + - status + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml new file mode 100644 index 0000000000..54787ae31f --- /dev/null +++ b/detections/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml @@ -0,0 +1,101 @@ +name: Windows AD Replication Request Initiated from Unsanctioned Location +id: 50998483-bb15-457b-a870-965080d9e3d3 +version: 1 +date: '2022-11-17' +author: Dean Luxton +type: TTP +datamodel: [] +description: This alert was written to detect activity associated with the DCSync attack performed by computer accounts. + When a domain controller receives a replication request, the account permissions are validated, however no checks are performed to validate the request was initiated by a Domain Controller. + Once an attacker gains control of an account with the necessary privileges, they can request password hashes for any or all users within the domain. + This alert detects when a computer account account creates a handle to domainDNS with the necessary replication permissions. These requests are then filtered to exclude where the events originate + from a known domain controller IP address. +search: '`wineventlog_security` EventCode=4662 ObjectType IN ("%{19195a5b-6da0-11d0-afd3-00c04fd930c9}", + "domainDNS") AND Properties IN ("*Replicating Directory Changes All*", "*{1131f6ad-9c07-11d1-f79f-00c04fc2dcd2}*", + "*{9923a32a-3607-11d2-b9be-0000f87a36b2}*","*{1131f6ac-9c07-11d1-f79f-00c04fc2dcd2}*") + AND AccessMask="0x100" AND (SubjectUserSid="NT AUT*" OR SubjectUserSid="S-1-5-18" OR SubjectDomainName="Window Manager" OR SubjectUserName="*$") + + | stats min(_time) as attack_time, count by SubjectDomainName, SubjectUserName, + Computer, Logon_ID, ObjectName, ObjectServer, ObjectType, OperationType, status + + | rename SubjectDomainName as Target_Domain, SubjectUserName as user, Logon_ID as + TargetLogonId + + | appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"] + + | table attack_time, AuthenticationPackageName, LogonProcessName, LogonType, TargetUserSid, + Target_Domain, user, Computer, TargetLogonId, status, src_ip, src_category, ObjectName, + ObjectServer, ObjectType, OperationType + + | stats min(attack_time) as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) + as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) + as status, values(src_category) as src_category, values(src_ip) as src_ip by TargetLogonId + + | search NOT src_category="domain_controller" | `windows_ad_replication_request_initiated_from_unsanctioned_location_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode `4662`. + The Advanced Security Audit policy settings `Audit Directory Services Access` + within `DS Access` needs to be enabled, as well as the following SACLs applied to the domain root + and all descendant objects. The principals `everybody`, `Domain Computers`, and `Domain Controllers` + auditing the permissions `Replicating Directory Changes`, `Replicating Directory Changes All`, and + `Replicating Directory Changes In Filtered Set` + Assets and Identities will also need to be configured, with the category of domain_controller added for domain controllers. +known_false_positives: Genuine DC promotion may trigger this alert. +references: +- https://adsecurity.org/?p=1729 +- https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer +- https://github.com/SigmaHQ/sigma/blob/0.22-699-g29a5c6278/rules/windows/builtin/security/win_security_dcsync.yml +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Credential Dumping + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Source:AD + - Stage:Credential Access + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Windows Active Directory Replication Request Initiated from Unsanctioned Location $src_ip$ by $user$ + mitre_attack_id: + - T1003.006 + - T1003 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_ip + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectType + - Properties + - AccessMask + - SubjectDomainName + - SubjectUserName + - SubjectUserSid + - Computer + - Logon_ID + - ObjectName + - ObjectServer + - ObjectType + - OperationType + - status + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml new file mode 100644 index 0000000000..5f33a7ff26 --- /dev/null +++ b/detections/endpoint/windows_ad_same_domain_sid_history_addition.yml @@ -0,0 +1,78 @@ +name: Windows AD Same Domain SID History Addition +id: 5fde0b7c-df7a-40b1-9b3a-294c00f0289d +version: 2 +date: '2022-09-09' +author: Dean Luxton +type: TTP +datamodel: [] +description: The following analytic looks for changes to the sIDHistory AD attribute of user or computer objects which exist within the same domain. + The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access + continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries to stealthily grant access to a backdoor account within the same domain. + This analytic was written to pick up on activity via Mimikatz sid::patch. Please note there are additional avenues to abuse SID history such as DCShadow & Golden / Diamond tickets which won't be detected using these event codes. +search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory + IN ("%%1793", -) + | rex field=SidHistory "(^%{|^)(?P.*)(\-|\\\)" + | rex field=TargetSid "^(?P.*)(\-|\\\)" + | where SidHistoryMatch=TargetSidmatch OR SidHistoryMatch=TargetDomainName + | rename TargetSid as userSid, TargetDomainName as userDomainName + | table _time action status host user userSid userDomainName SidHistory Logon_ID src_user + | `windows_ad_same_domain_sid_history_addition_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcodes + `4738` and `4742`. The Advanced Security Audit policy settings + `Audit User Account Management` and `Audit Computer Account Management` + within `Account Management` all need to be enabled. SID resolution is not required.. +known_false_positives: Unknown +references: +- https://adsecurity.org/?p=1772 +- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN +- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute +- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + - Windows Persistence Techniques + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + - CIS 16 + confidence: 100 + context: + - Source:AD + - Stage:Persistence + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Active Directory SID History Attribute was added to $user$ by $src_user$ + mitre_attack_id: + - T1134.005 + - T1134 + nist: + - DE.CM + observable: + - name: src_user + type: User + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - SidHistory + - TargetSid + - TargetDomainName + - user + - src_user + - Logon_ID + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml b/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml new file mode 100644 index 0000000000..c0a7a9b437 --- /dev/null +++ b/detections/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml @@ -0,0 +1,69 @@ +name: Windows AD ServicePrincipalName Added To Domain Account +id: 8a1259cb-0ea7-409c-8bfe-74bad89259f9 +version: 1 +date: '2022-11-17' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic identifies the addition of a Service Principal Name to a domain account. While this event may be part of a legitimate action part of certain administrative operations, + it may also be evidence of a persistence attack. Domain accounts with Servce Principal Names are vulnerable to a technique called Kerberoasting that enables attackers to potentially obtain the cleartext password + of the account by performing offline cracking. An adversary who has obtained privileged access to a domain environment may add an SPN to a privileged account to then leverage the Kerberoasting technique and attempt + to obtain its clertext password. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName OperationType="%%14674" + | stats values(ObjectDN) by _time, Computer, SubjectUserName, AttributeValue + | `windows_ad_serviceprincipalname_added_to_domain_account_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications. +known_false_positives: A Service Principal Name should only be added to an account when an application requires it. While infrequent, this detection may trigger on + legitimate actions. Filter as needed. +references: +- https://adsecurity.org/?p=3466 +- https://www.thehacker.recipes/ad/movement/dacl/targeted-kerberoasting +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 +- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting +tags: + analytic_story: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 50 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log + impact: 60 + kill_chain_phases: + - Installation + - Actions on Objectives + message: A Servince Principal Name for $ObjectDN$ was set by $SubjectUserName$ + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: ObjectDN + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectDN + - signature + - SubjectUserName + - Computer + risk_score: 30 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml b/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml new file mode 100644 index 0000000000..00364ccf19 --- /dev/null +++ b/detections/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml @@ -0,0 +1,71 @@ +name: Windows AD Short Lived Domain Account ServicePrincipalName +id: b681977c-d90c-4efc-81a5-c58f945fb541 +version: 1 +date: '2022-11-18' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic identifies the addition of a Service Principal Name to a domain account that is quickly deleted within 5 minutes or less. While this event may be part of a legitimate action part of certain administrative operations, + it may also be evidence of a persistence attack. Domain accounts with Service Principal Names are vulnerable to a technique called Kerberoasting that enables attackers to potentially obtain the cleartext password + of the account by performing offline cracking. An adversary who has obtained privileged access to a domain environment may add an SPN to a privileged account to then leverage the Kerberoasting technique and attempt + to obtain its clertext password. To clean things up, the adversary may delete the SPN which will trigger this detection. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName + | transaction ObjectDN AttributeValue startswith=(EventCode=5136 OperationType="%%14674") endswith=(EventCode=5136 OperationType="%%14675") + | eval short_lived=case((duration<300),"TRUE") + | search short_lived = TRUE + | `windows_ad_short_lived_domain_account_serviceprincipalname_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications. +known_false_positives: A Service Principal Name should only be added to an account when an application requires it. Adding an SPN and quickly deleting it + is less common but may be part of legitimate action. Filter as needed. +references: +- https://adsecurity.org/?p=3466 +- https://www.thehacker.recipes/ad/movement/dacl/targeted-kerberoasting +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5136 +- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/short_lived_service_principal_name/windows-security.log + impact: 50 + kill_chain_phases: + - Installation + - Actions on Objectives + message: A Servince Principal Name for $ObjectDN$ was set and shortly deleted + mitre_attack_id: + - T1098 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: ObjectDN + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectDN + - signature + - SubjectUserName + - Computer + risk_score: 40 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml b/detections/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml new file mode 100644 index 0000000000..e833fc8f8c --- /dev/null +++ b/detections/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml @@ -0,0 +1,78 @@ +name: Windows AD Short Lived Domain Controller SPN Attribute +id: 57e27f27-369c-4df8-af08-e8c7ee8373d4 +version: 2 +date: '2022-09-02' +author: Dean Luxton +type: TTP +datamodel: [] +description: The following analytic identifies when either a global catalog SPN or a DRS RPC SPN are temporarily added to an Active Directory computer object, both of which can be evidence of a DCShadow attack. + DCShadow allows an attacker who has obtained privileged access to register a rogue Domain Controller (DC). Once registered, the rogue DC may be able to inject + and replicate changes into the AD infrastructure for any domain object, including credentials and keys. This technique was initially released in 2018 by security researchers Benjamin Delpy and Vincent Le Toux. + No event logs are written for changes to AD attributes, allowing for stealthy backdoors to be implanted in the domain, or metadata such as timestamps overwritten to cover tracks. +search: '`wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=servicePrincipalName (AttributeValue="GC/*" OR AttributeValue="E3514235-4B06-11D1-AB04-00C04FC2DCD2/*") + | stats min(_time) as _time range(_time) as duration values(OperationType) as OperationType values(src_nt_domain) as src_nt_domain values(src_user) as src_user values(Computer) as Computer, values(ObjectDN) as ObjectDN by Logon_ID + | eval short_lived=case((duration<30),"TRUE") + | where short_lived="TRUE" AND mvcount(OperationType)>1 + | replace "%%14674" with "Value Added", "%%14675" with "Value Deleted" in OperationType + | rename Logon_ID as TargetLogonId + | appendpipe [| map search="search `wineventlog_security` EventCode=4624 TargetLogonId=$TargetLogonId$"] + | stats min(_time) as _time, values(TargetUserSid) as TargetUserSid, values(Target_Domain) as Target_Domain, values(user) as user, values(Computer) as Computer, values(status) as status, values(src_category) as src_category, values(src_ip) as src_ip values(ObjectDN) as ObjectDN values(OperationType) as OperationType by TargetLogonId + | `windows_ad_short_lived_domain_controller_spn_attribute_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled, alongside a SACL for `everybody` to + `Write All Properties` applied to the domain root and all descendant objects. +known_false_positives: None. +references: +- https://www.dcshadow.com/ +- https://blog.netwrix.com/2022/09/28/dcshadow_attack/ +- https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2 +- https://attack.mitre.org/techniques/T1207/ +- https://blog.alsid.eu/dcshadow-explained-4510f52fc19d +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Short Lived Domain Controller SPN AD Attribute Triggered by $user$ from $src_ip$ + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_ip + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AttributeLDAPDisplayName + - AttributeValue + - src_nt_domain + - src_user + - Computer + - ObjectDN + - Logon_ID + - signature + risk_score: 100 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_short_lived_server_object.yml b/detections/endpoint/windows_ad_short_lived_server_object.yml new file mode 100644 index 0000000000..ed5b2cf8c9 --- /dev/null +++ b/detections/endpoint/windows_ad_short_lived_server_object.yml @@ -0,0 +1,77 @@ +name: Windows AD Short Lived Server Object +id: 193769d3-1e33-43a9-970e-ad4a88256cdb +version: 1 +date: '2022-10-17' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: 'The following analytic identifies a change in an Active Directory environment that could represent evidence of the DCShadow attack. + DCShadow allows an attacker who has obtained privileged access to register a rogue Domain Controller (DC). Once registered, the rogue DC may be able to inject + and replicate changes in the AD infrastructure for any domain object, including credentials and keys. This technique was initially released in 2018 by security + researchers Benjamin Delpy and Vincent Le Toux. Specifically, the detection will trigger when a possible rogue Domain Controller + computer object is created and quickly deleted within 30 seconds or less in an Active Directory domain. This behavior was identfied by simulating the DCShadow attack with + Mimikatz.' +search: ' `wineventlog_security` EventCode=5137 OR EventCode=5141 ObjectDN="*CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration*" + | transaction ObjectDN startswith=(EventCode=5137) endswith=(EventCode=5141) + | eval short_lived=case((duration<30),"TRUE") + | search short_lived = TRUE + | stats values(ObjectDN) values(signature) values(EventCode) by _time, Computer, SubjectUserName + | `windows_ad_short_lived_server_object_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting Event codes + `5137` and `5141`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. For these event codes to be generated, specific SACLs are required. +known_false_positives: Creating and deleting a server object within 30 seconds or less is unusual but not impossible in a production environment. Filter as needed. +references: +- https://www.dcshadow.com/ +- https://attack.mitre.org/techniques/T1207/ +- https://stealthbits.com/blog/detecting-dcshadow-with-event-logs/ +- https://pentestlab.blog/2018/04/16/dcshadow/ +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5137 +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-5141 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + - Stage:Privilege Escalation + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/short_lived_server_object/windows-security.log + impact: 80 + kill_chain_phases: + - Installation + - Actions on Objectives + message: Potential DCShadow Attack Detected on $Computer$ + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + - name: Computer + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - ObjectDN + - signature + - SubjectUserName + - Computer + risk_score: 64 + security_domain: endpoint diff --git a/detections/endpoint/windows_ad_sid_history_attribute_modified.yml b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml new file mode 100644 index 0000000000..d87b775222 --- /dev/null +++ b/detections/endpoint/windows_ad_sid_history_attribute_modified.yml @@ -0,0 +1,66 @@ +name: Windows AD SID History Attribute Modified +id: 1155e47d-307f-4247-beab-71071e3a458c +version: 1 +date: '2022-11-16' +author: Mauricio Velazco, Splunk +type: TTP +datamodel: [] +description: The following analytic leverages event code `5136` to identify a modification of the SID History AD attribute. + The SID history AD attribute allows users to inherit permissions from a separate AD account without group changes. Initially developed for access + continuity when migrating user accounts to different domains, this attribute can also be abused by adversaries to stealthily grant access to a backdoor account within the same domain. +search: ' `wineventlog_security` EventCode=5136 AttributeLDAPDisplayName=sIDHistory OperationType="%%14674" + | stats values(ObjectDN) by _time, Computer, SubjectUserName, AttributeValue + | `windows_ad_sid_history_attribute_modified_filter`' +how_to_implement: To successfully implement this search, you ned to be ingesting eventcode + `5136`. The Advanced Security Audit policy setting `Audit Directory Services Changes` + within `DS Access` needs to be enabled. Additionally, a SACL needs to be created for AD objects in order to ingest attribute modifications. +known_false_positives: Domain mergers and migrations may generate large volumes of false positives for this analytic. +references: +- https://adsecurity.org/?p=1772 +- https://learn.microsoft.com/en-us/windows/win32/adschema/a-sidhistory?redirectedfrom=MSDN +- https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-unsecure-sid-history-attribute +- https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/sid-history-injection +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 70 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/sid_history2/windows-security.log + impact: 80 + kill_chain_phases: + - Installation + - Actions on Objectives + message: SID History AD attribute modified by $SubjectUserName$ for $ObjectDN$ + mitre_attack_id: + - T1134 + - T1134.005 + nist: + - DE.CM + observable: + - name: SubjectUserName + type: User + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AttributeLDAPDisplayName + - OperationType= + - ObjectDN + - Computer + - SubjectUserName + - AttributeValue + risk_score: 56 + security_domain: endpoint diff --git a/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml b/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml index 46d579f45e..e3ab45ab81 100644 --- a/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml +++ b/detections/endpoint/windows_disable_windows_group_policy_features_through_registry.yml @@ -1,18 +1,14 @@ name: Windows Disable Windows Group Policy Features Through Registry id: 63a449ae-9f04-11ec-945e-acde48001122 -version: 2 +version: 3 date: '2022-11-14' author: Steven Dick, Teoderick Contreras, Splunk type: Anomaly datamodel: - Endpoint -description: This analytic is to detect a suspicious registry modification to disable - windows features. These techniques are seen in several ransomware malware to impair - the compromised host to make it hard for analyst to mitigate or response from the - attack. Disabling these known features make the analysis and forensic response more - hard. Disabling these feature is not so common but can still be implemented by the - administrator for security purposes. In this scenario filters for users that are - allowed doing this is needed. +description: The following analytic detects a suspicious registry modification used to disable + windows features. This technique has been identified in several ransomware malware families to impair + the compromised host and make it harder for analysts to mitigate or respond to an attack. search: '| tstats `security_content_summariesonly` count min(_time) AS firstTime max(_time) AS lastTime FROM datamodel=Endpoint.Processes BY _time span=1h Processes.user Processes.process_id Processes.process_name Processes.process Processes.process_path Processes.dest Processes.parent_process_name Processes.parent_process Processes.process_guid | `drop_dm_object_name(Processes)` | join process_guid [ @@ -27,7 +23,8 @@ how_to_implement: To successfully implement this search, you need to be ingestin logs with the registry value name, registry path, and registry value data from your endpoints. If you are using Sysmon, you must have at least version 2.0 of the offical Sysmon TA. https://splunkbase.splunk.com/app/5709 -known_false_positives: unknown +known_false_positives: Disabling these features for legitimate purposes is not a common use case but can still be implemented by the + administrators. Filter as needed. references: - https://hybrid-analysis.com/sample/ef1c427394c205580576d18ba68d5911089c7da0386f19d1ca126929d3e671ab?environmentId=120&lang=en - https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~Krotten-N/detailed-analysis @@ -37,6 +34,7 @@ tags: - Ransomware - Windows Defense Evasion Tactics - Windows Registry Abuse + - Sneaky Active Directory Persistence Tricks dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/ransomware_disable_reg/sysmon.log kill_chain_phases: diff --git a/detections/endpoint/windows_security_support_provider_reg_query.yml b/detections/endpoint/windows_security_support_provider_reg_query.yml index 967b7ea5c0..5efe828ec5 100644 --- a/detections/endpoint/windows_security_support_provider_reg_query.yml +++ b/detections/endpoint/windows_security_support_provider_reg_query.yml @@ -32,6 +32,7 @@ tags: analytic_story: - Windows Post-Exploitation - Prestige Ransomware + - Sneaky Active Directory Persistence Tricks asset_type: Endpoint cis20: - CIS 3 diff --git a/detections/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml b/detections/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml new file mode 100644 index 0000000000..a40e4e2f62 --- /dev/null +++ b/detections/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.yml @@ -0,0 +1,64 @@ +name: Windows AD Domain Controller Audit Policy Disabled +id: fc3ccef1-60a4-4239-bd66-b279511b4d14 +version: 1 +date: '2023-01-26' +author: Dean Luxton +type: TTP +datamodel: [] +description: This analytic looks for audit policies being disabled on a domain controller. +search: '`wineventlog_security` EventCode=4719 (AuditPolicyChanges IN ("%%8448","%%8450","%%8448, + %%8450") OR Changes IN ("Failure removed","Success removed","Success removed, Failure + removed")) dest_category="domain_controller" + + | replace "%%8448" with "Success removed", "%%8450" with "Failure removed", "%%8448, + %%8450" with "Success removed, Failure removed" in AuditPolicyChanges + + | eval AuditPolicyChanges=coalesce(AuditPolicyChanges,Changes), SubcategoryGuid=coalesce(SubcategoryGuid,Subcategory_GUID) + + | stats min(_time) as _time values(host) as dest by AuditPolicyChanges SubcategoryGuid + + | lookup advanced_audit_policy_guids GUID as SubcategoryGuid OUTPUT Category SubCategory + | `windows_ad_domain_controller_audit_policy_disabled_filter`' +how_to_implement: Ensure you are ingesting EventCode `4719` from your domain controllers, the category domain_controller exists + in assets and identities, and that assets and identities is enabled. If A&I is not configured, you will need to manually filter the results + within the base search. +known_false_positives: Unknown +references: +- https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4719 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 60 + context: + - Source:Endpoint + - Stage:Defense Evasion + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_gpo/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: GPO $SubCategory$ of $Category$ was disabled on $dest$ + mitre_attack_id: + - T1562.001 + nist: + - DE.CM + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - AuditPolicyChanges + - SubcategoryGuid + risk_score: 60 + security_domain: endpoint diff --git a/detections/experimental/endpoint/windows_ad_domain_replication_acl_addition.yml b/detections/experimental/endpoint/windows_ad_domain_replication_acl_addition.yml new file mode 100644 index 0000000000..ff73722cfc --- /dev/null +++ b/detections/experimental/endpoint/windows_ad_domain_replication_acl_addition.yml @@ -0,0 +1,89 @@ +name: Windows AD Domain Replication ACL Addition +id: 8c372853-f459-4995-afdc-280c114d33ab +version: 1 +date: '2022-11-18' +author: Dean Luxton +type: TTP +datamodel: [] +description: This analytic detects the addition of the permissions necessary to perform a DCSync attack. + In order to replicate AD objects, the initiating user or computer must have the following permissions on the domain. + - DS-Replication-Get-Changes + - DS-Replication-Get-Changes-All + Certain Sync operations may require the additional permission of DS-Replication-Get-Changes-In-Filtered-Set. + By default, adding DCSync permissions via the Powerview Add-ObjectACL operation adds all 3. This alert identifies where this trifecta has been met, and also where just the base level requirements have been met. +search: "`wineventlog_security` (EventCode=5136) AttributeLDAPDisplayName=\"ntSecurityDescriptor\"\ + \ \"1131f6ad-9c07-11d1-f79f-00c04fc2dcd2\" OR \"1131f6aa-9c07-11d1-f79f-00c04fc2dcd2\"\ + \ OR \"89e95b76-444d-4c62-991a-0facbeda640c\" \n| where AttributeValue like \"%1131f6ad-9c07-11d1-f79f-00c04fc2dcd2%\"\ + \ AND AttributeValue like \"%1131f6aa-9c07-11d1-f79f-00c04fc2dcd2%\" AND AttributeValue\ + \ like \"%89e95b76-444d-4c62-991a-0facbeda640c%\" \n| search NOT ObjectClass IN\ + \ (dnsNode,dnsZoneScope,dnsZone)\n| rex field=AttributeValue max_match=10000 \"\ + OA;;CR;1131f6aa-9c07-11d1-f79f-00c04fc2dcd2;;(?PS-1-[0-59]-\\\ + d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| rex field=AttributeValue\ + \ max_match=10000 \"OA;;CR;1131f6ad-9c07-11d1-f79f-00c04fc2dcd2;;(?PS-1-[0-59]-\\\ + d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| rex field=AttributeValue\ + \ max_match=10000 \"OA;;CR;89e95b76-444d-4c62-991a-0facbeda640c;;(?PS-1-[0-59]-\\\ + d{2}-\\d{8,10}-\\d{8,10}-\\d{8,10}-[1-9]\\d{3})\\)\"\n| table _time dest src_user DSRGetChanges_user_sid\ + \ DSRGetChangesAll_user_sid DSRGetChangesFiltered_user_sid\n| mvexpand DSRGetChanges_user_sid\n\ + | eval minDCSyncPermissions=if(DSRGetChanges_user_sid=DSRGetChangesAll_user_sid,\"\ + true\",\"false\"), fullSet=if(DSRGetChanges_user_sid=DSRGetChangesAll_user_sid AND\ + \ DSRGetChanges_user_sid=DSRGetChangesFiltered_user_sid,\"true\",\"false\")\n| where\ + \ minDCSyncPermissions=\"true\"\n| lookup identity_lookup_expanded objectSid as\ + \ DSRGetChanges_user_sid OUTPUT sAMAccountName as user\n| rename DSRGetChanges_user_sid\ + \ as userSid\n| stats min(_time) as _time values(user) as user by dest src_user userSid minDCSyncPermissions fullSet|\ + \ `windows_ad_domain_replication_acl_addition_filter`" +how_to_implement: To successfully implement this search, you need to be ingesting the eventcode 5136. The Advanced Security Audit policy setting + `Audit Directory Services Changes` within `DS Access` needs to be enabled, alongside a SACL for `everybody` to `Write All Properties` + applied to the domain root and all descendant objects. Once the necessary logging has been enabled, enumerate the domain policy to verify if existing + accounts with access need to be whitelisted, or revoked. Assets and Identities is also leveraged to automatically translate the objectSid into username. + Ensure your identities lookup is configured with the sAMAccountName and objectSid of all AD user and computer objects. +known_false_positives: When there is a change to nTSecurityDescriptor, Windows logs the entire ACL with the newly added components. + If existing accounts are present with this permission, they will raise an alert each time the nTSecurityDescriptor is updated unless whitelisted. +references: +- https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/1522b774-6464-41a3-87a5-1e5633c3fbbb +- https://github.com/SigmaHQ/sigma/blob/29a5c62784faf986dc03952ae3e90e3df3294284/rules/windows/builtin/security/win_security_account_backdoor_dcsync_rights.yml +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 6 + confidence: 80 + context: + - Source:Endpoint + - Stage:Persistence + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/aclmodification/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: $src_user$ has granted $user$ permission to replicate AD objects + mitre_attack_id: + - T1484 + nist: + - DE.CM + observable: + - name: user + type: User + role: + - Victim + - name: src_user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - src_user + - AttributeLDAPDisplayName + - AttributeValue + - ObjectClass + risk_score: 80 + security_domain: endpoint diff --git a/detections/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.yml b/detections/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.yml new file mode 100644 index 0000000000..1b3c5a3f25 --- /dev/null +++ b/detections/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.yml @@ -0,0 +1,77 @@ +name: Windows AD Privileged Account SID History Addition +id: 6b521149-b91c-43aa-ba97-c2cac59ec830 +version: 1 +date: '2022-09-12' +author: Dean Luxton +type: TTP +datamodel: [] +description: This detection identifies when the SID of a privileged user is added to + the SID History attribute of another user. Useful for tracking SID history abuse + across multiple domains. This detection leverages the Asset and Identities + framework. See the implementation section for further details on configuration. +search: '`wineventlog_security` (EventCode=4742 OR EventCode=4738) NOT SidHistory IN ("%%1793", -) + | rex field=SidHistory "(^%{|^)(?P.*?)(}$|$)" + | eval category="privileged" + | lookup identity_lookup_expanded category, identity as SidHistory OUTPUT identity_tag as match + | where isnotnull(match) + | rename TargetSid as userSid + | table _time action status host user userSid SidHistory Logon_ID src_user + | `windows_active_directory_privileged_account_sid_history_addition_filter`' +how_to_implement: Ensure you have objectSid and the Down Level Logon Name `DOMAIN\sAMACountName` + added to the identity field of your Asset and Identities lookup, along with the + category of privileged for the applicable users. Ensure you are + ingesting eventcodes 4742 and 4738. Two advanced audit policies + `Audit User Account Management` and `Audit Computer Account Management` under + `Account Management` are required to generate these event codes. +known_false_positives: Migration of privileged accounts. +references: +- https://adsecurity.org/?p=1772 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + - CIS 16 + confidence: 90 + context: + - Source:Endpoint + - Source:AD + - Stage:Defense Evasion + - Stage:Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: A Privileged User Account SID History Attribute was added to $user$ by $src_user$ + mitre_attack_id: + - T1134.005 + - T1134 + nist: + - DE.CM + observable: + - name: src_user + type: User + role: + - Victim + - name: user + type: User + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - EventCode + - SidHistory + - TargetSid + - TargetDomainName + - user + - src_user + - Logon_ID + risk_score: 90 + security_domain: endpoint diff --git a/detections/experimental/network/windows_ad_replication_service_traffic.yml b/detections/experimental/network/windows_ad_replication_service_traffic.yml new file mode 100644 index 0000000000..3d862b148d --- /dev/null +++ b/detections/experimental/network/windows_ad_replication_service_traffic.yml @@ -0,0 +1,72 @@ +name: Windows AD Replication Service Traffic +id: c6e24183-a5f4-4b2a-ad01-2eb456d09b67 +version: 1 +date: '2022-11-26' +author: Steven Dick +type: TTP +datamodel: +- Network_Traffic +- Network_Sessions +description: This search looks for evidence of Active Directory replication traffic [MS-DRSR] from unexpected sources. + This traffic is often seen exclusively between Domain Controllers for AD database replication. + Any detections from non-domain controller source to a domain controller may indicate the usage of DCSync or DCShadow credential dumping techniques. +search: ' | tstats `security_content_summariesonly` count values(All_Traffic.transport) as transport values(All_Traffic.user) as user + values(All_Traffic.src_category) as src_category values(All_Traffic.dest_category) as dest_category min(_time) as firstTime max(_time) as lastTime + from datamodel=Network_Traffic where All_Traffic.app IN ("ms-dc-replication","*drsr*","ad drs") by All_Traffic.src All_Traffic.dest All_Traffic.app + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` + | `drop_dm_object_name("All_Traffic")` + | `active_directory_replication_traffic_from_unknown_source_filter` + | `windows_ad_replication_service_traffic_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + application aware firewall or proxy logs into the Network Datamodel. Categorize + all known domain controller Assets servers with an appropriate category for filtering. +known_false_positives: New domain controllers or certian scripts run by administrators. +references: +- https://adsecurity.org/?p=1729 +- https://attack.mitre.org/techniques/T1003/006/ +- https://attack.mitre.org/techniques/T1207/ +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: endpoint + cis20: + - CIS 3 + - CIS 5 + - CIS 16 + confidence: 100 + context: + - Source:Endpoint + - Stage:Credential Access + dataset: + - UPDATE_DATASET_URL + impact: 100 + kill_chain_phases: + - Exploitation + - Actions on Objectives + message: Active Directory Replication Traffic from Unknown Source - $src$ + mitre_attack_id: + - T1003 + - T1003.006 + - T1207 + nist: + - DE.CM + observable: + - name: dest + type: IP Address + role: + - Victim + - name: src + type: IP Address + role: + - Attacker + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - All_Traffic.src + - All_Traffic.dest + - All_Traffic.app + risk_score: 100 + security_domain: network diff --git a/detections/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml b/detections/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml new file mode 100644 index 0000000000..fb8a711cbd --- /dev/null +++ b/detections/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml @@ -0,0 +1,57 @@ +name: Windows AD Rogue Domain Controller Network Activity +id: c4aeeeef-da7f-4338-b3ba-553cbcbe2138 +version: 1 +date: '2022-09-08' +author: Dean Luxton +type: TTP +datamodel: [] +description: This detection is looking at zeek wiredata for specific replication RPC calls being performed from a device which is not a domain controller. + If you would like to capture these RPC calls using Splunk Stream, please vote for my idea here https://ideas.splunk.com/ideas/APPSID-I-619 ;) +search: '`zeek_rpc` DrsReplicaAdd OR DRSGetNCChanges + | where NOT (dest_category="Domain Controller") OR NOT (src_category="Domain Controller") + | fillnull value="Unknown" src_category, dest_category + | table _time endpoint operation src src_category dest dest_category | `rogue_dc_network_activity_filter`' +how_to_implement: Run zeek on domain controllers to capture the DCE RPC calls, ensure the domain controller categories are defined in Assets and Identities. +known_false_positives: None. +references: +- https://adsecurity.org/?p=1729 +tags: + analytic_story: + - Sneaky Active Directory Persistence Tricks + asset_type: Endpoint + cis20: + - CIS 4 + - CIS 6 + confidence: 100 + context: + - Source:IPS + - Stage:Defense Evasion + dataset: + - https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1207/mimikatz/zeek-dce_rpc.log + impact: 100 + kill_chain_phases: + - Actions on Objectives + message: Rogue DC Activity Detected from $src_category$ device $src$ to $dest$ ($dest_category$) + mitre_attack_id: + - T1207 + nist: + - DE.CM + observable: + - name: src + type: IP Address + role: + - Attacker + - name: dest + type: IP Address + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - src + - dest + risk_score: 100 + security_domain: network diff --git a/lookups/advanced_audit_policy_guids.csv b/lookups/advanced_audit_policy_guids.csv new file mode 100644 index 0000000000..646c8914a8 --- /dev/null +++ b/lookups/advanced_audit_policy_guids.csv @@ -0,0 +1,69 @@ +Category,SubCategory,GUID +System,,{69979848-797A-11D9-BED3-505054503030} +System,Security State Change,{0CCE9210-69AE-11D9-BED3-505054503030} +System,Security System Extension,{0CCE9211-69AE-11D9-BED3-505054503030} +System,System Integrity,{0CCE9212-69AE-11D9-BED3-505054503030} +System,IPsec Driver,{0CCE9213-69AE-11D9-BED3-505054503030} +System,Other System Events,{0CCE9214-69AE-11D9-BED3-505054503030} +Logon/Logoff,,{69979849-797A-11D9-BED3-505054503030} +Logon/Logoff,Logon,{0CCE9215-69AE-11D9-BED3-505054503030} +Logon/Logoff,Logoff,{0CCE9216-69AE-11D9-BED3-505054503030} +Logon/Logoff,Account Lockout,{0CCE9217-69AE-11D9-BED3-505054503030} +Logon/Logoff,IPsec Main Mode,{0CCE9218-69AE-11D9-BED3-505054503030} +Logon/Logoff,IPsec Quick Mode,{0CCE9219-69AE-11D9-BED3-505054503030} +Logon/Logoff,IPsec Extended Mode,{0CCE921A-69AE-11D9-BED3-505054503030} +Logon/Logoff,Special Logon,{0CCE921B-69AE-11D9-BED3-505054503030} +Logon/Logoff,Other Logon/Logoff Events,{0CCE921C-69AE-11D9-BED3-505054503030} +Logon/Logoff,Network Policy Server,{0CCE9243-69AE-11D9-BED3-505054503030} +Logon/Logoff,User / Device Claims,{0CCE9247-69AE-11D9-BED3-505054503030} +Logon/Logoff,Group Membership,{0CCE9249-69AE-11D9-BED3-505054503030} +Object Access,,{6997984A-797A-11D9-BED3-505054503030} +Object Access,File System,{0CCE921D-69AE-11D9-BED3-505054503030} +Object Access,Registry,{0CCE921E-69AE-11D9-BED3-505054503030} +Object Access,Kernel Object,{0CCE921F-69AE-11D9-BED3-505054503030} +Object Access,SAM,{0CCE9220-69AE-11D9-BED3-505054503030} +Object Access,Certification Services,{0CCE9221-69AE-11D9-BED3-505054503030} +Object Access,Application Generated,{0CCE9222-69AE-11D9-BED3-505054503030} +Object Access,Handle Manipulation,{0CCE9223-69AE-11D9-BED3-505054503030} +Object Access,File Share,{0CCE9224-69AE-11D9-BED3-505054503030} +Object Access,Filtering Platform Packet Drop,{0CCE9225-69AE-11D9-BED3-505054503030} +Object Access,Filtering Platform Connection,{0CCE9226-69AE-11D9-BED3-505054503030} +Object Access,Other Object Access Events,{0CCE9227-69AE-11D9-BED3-505054503030} +Object Access,Detailed File Share,{0CCE9244-69AE-11D9-BED3-505054503030} +Object Access,Removable Storage,{0CCE9245-69AE-11D9-BED3-505054503030} +Object Access,Central Policy Staging,{0CCE9246-69AE-11D9-BED3-505054503030} +Privilege Use,,{6997984B-797A-11D9-BED3-505054503030} +Privilege Use,Sensitive Privilege Use,{0CCE9228-69AE-11D9-BED3-505054503030} +Privilege Use,Non Sensitive Privilege Use,{0CCE9229-69AE-11D9-BED3-505054503030} +Privilege Use,Other Privilege Use Events,{0CCE922A-69AE-11D9-BED3-505054503030} +Detailed Tracking,,{6997984C-797A-11D9-BED3-505054503030} +Detailed Tracking,Process Creation,{0CCE922B-69AE-11D9-BED3-505054503030} +Detailed Tracking,Process Termination,{0CCE922C-69AE-11D9-BED3-505054503030} +Detailed Tracking,DPAPI Activity,{0CCE922D-69AE-11D9-BED3-505054503030} +Detailed Tracking,RPC Events,{0CCE922E-69AE-11D9-BED3-505054503030} +Detailed Tracking,Plug and Play Events,{0CCE9248-69AE-11D9-BED3-505054503030} +Detailed Tracking,Token Right Adjusted Events,{0CCE924A-69AE-11D9-BED3-505054503030} +Policy Change,,{6997984D-797A-11D9-BED3-505054503030} +Policy Change,Audit Policy Change,{0CCE922F-69AE-11D9-BED3-505054503030} +Policy Change,Authentication Policy Change,{0CCE9230-69AE-11D9-BED3-505054503030} +Policy Change,Authorization Policy Change,{0CCE9231-69AE-11D9-BED3-505054503030} +Policy Change,MPSSVC Rule-Level Policy Change,{0CCE9232-69AE-11D9-BED3-505054503030} +Policy Change,Filtering Platform Policy Change,{0CCE9233-69AE-11D9-BED3-505054503030} +Policy Change,Other Policy Change Events,{0CCE9234-69AE-11D9-BED3-505054503030} +Account Management,,{6997984E-797A-11D9-BED3-505054503030} +Account Management,User Account Management,{0CCE9235-69AE-11D9-BED3-505054503030} +Account Management,Computer Account Management,{0CCE9236-69AE-11D9-BED3-505054503030} +Account Management,Security Group Management,{0CCE9237-69AE-11D9-BED3-505054503030} +Account Management,Distribution Group Management,{0CCE9238-69AE-11D9-BED3-505054503030} +Account Management,Application Group Management,{0CCE9239-69AE-11D9-BED3-505054503030} +Account Management,Other Account Management Events,{0CCE923A-69AE-11D9-BED3-505054503030} +DS Access,,{6997984F-797A-11D9-BED3-505054503030} +DS Access,Directory Service Access,{0CCE923B-69AE-11D9-BED3-505054503030} +DS Access,Directory Service Changes,{0CCE923C-69AE-11D9-BED3-505054503030} +DS Access,Directory Service Replication,{0CCE923D-69AE-11D9-BED3-505054503030} +DS Access,Detailed Directory Service Replication,{0CCE923E-69AE-11D9-BED3-505054503030} +Account Logon,,{69979850-797A-11D9-BED3-505054503030} +Account Logon,Credential Validation,{0CCE923F-69AE-11D9-BED3-505054503030} +Account Logon,Kerberos Service Ticket Operations,{0CCE9240-69AE-11D9-BED3-505054503030} +Account Logon,Other Account Logon Events,{0CCE9241-69AE-11D9-BED3-505054503030} +Account Logon,Kerberos Authentication Service,{0CCE9242-69AE-11D9-BED3-505054503030} \ No newline at end of file diff --git a/lookups/advanced_audit_policy_guids.yml b/lookups/advanced_audit_policy_guids.yml new file mode 100644 index 0000000000..37b6e854af --- /dev/null +++ b/lookups/advanced_audit_policy_guids.yml @@ -0,0 +1,7 @@ +description: List of GUIDs associated with Windows advanced audit policies +filename: advanced_audit_policy_guids.csv +name: advanced_audit_policy_guids +default_match: 'false' +match_type: WILDCARD(GUID) +min_matches: 1 +case_sensitive_match: 'false' \ No newline at end of file diff --git a/macros/wineventlog_security.yml b/macros/wineventlog_security.yml index cfbe346e92..65bed12450 100644 --- a/macros/wineventlog_security.yml +++ b/macros/wineventlog_security.yml @@ -1,4 +1,4 @@ -definition: eventtype=wineventlog_security OR source="XmlWinEventLog:Security" +definition: eventtype=wineventlog_security OR Channel=security OR source=XmlWinEventLog:Security description: customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent. name: wineventlog_security diff --git a/stories/sneaky_active_directory_persistence_tricks.yml b/stories/sneaky_active_directory_persistence_tricks.yml new file mode 100644 index 0000000000..3b579b4f9a --- /dev/null +++ b/stories/sneaky_active_directory_persistence_tricks.yml @@ -0,0 +1,37 @@ +name: Sneaky Active Directory Persistence Tricks +id: f676c4c1-c769-4ecb-9611-5fd85b497c56 +version: 1 +date: '2022-08-29' +author: Dean Luxton, Mauricio Velazco, Splunk +description: Monitor for activities and techniques associated with Windows Active Directory persistence techniques. +narrative: Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. + Active Directory is a centralized and hierarchical database that stores information about users, computers, and other resources on a network. It provides secure and efficient management + of these resources and enables administrators to enforce security policies and delegate administrative tasks.\ + + In 2015 Active Directory security researcher Sean Metcalf published a blog post titled `Sneaky Active Directory Persistence Tricks`. In this blog post, + Sean described several methods through which an attacker could persist administrative access on an Active Directory network after having Domain Admin level rights for + a short period of time. At the time of writing, 8 years after the initial blog post, most of these techniques are still possible since they abuse legitimate administrative functionality and not software vulnerabilities. + Security engineers defending Active Directory networks should be aware of these technique available to adversaries post exploitation and deploy both preventive and detective security controls for them.\ + + This analytic story groups detection opportunities for most of the techniques described on Seans blog post as well as other high impact attacks against Active Directory networks and Domain Controllers like DCSync and DCShadow. + For some of these detection opportunities, it is necessary to enable the necessary GPOs and SACLs required, otherwise the event codes will not trigger. Each detection includes a list of requirements for enabling logging. +references: + - https://adsecurity.org/?p=1929 + - https://www.youtube.com/watch?v=Lz6haohGAMc&feature=youtu.be + - https://adsecurity.org/wp-content/uploads/2015/09/DEFCON23-2015-Metcalf-RedvsBlue-ADAttackAndDefense-Final.pdf + - https://attack.mitre.org/tactics/TA0003/ + - https://www.dcshadow.com + - https://gist.github.com/gentilkiwi/dcc132457408cf11ad2061340dcb53c2 + - https://www.linkedin.com/pulse/mimikatz-dcsync-event-log-detections-john-dwyer +tags: + analytic_story: Windows Domain Controller Attacks + category: + - Adversary Tactics + - Account Compromise + - Lateral Movement + - Privilege Escalation + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection diff --git a/tests/endpoint/disabling_windows_local_security_authority_defences_via_registry.test.yml b/tests/endpoint/disabling_windows_local_security_authority_defences_via_registry.test.yml new file mode 100644 index 0000000000..4ca8e90ad4 --- /dev/null +++ b/tests/endpoint/disabling_windows_local_security_authority_defences_via_registry.test.yml @@ -0,0 +1,13 @@ +name: Disabling Windows Local Security Authority Defences via Registry Unit Test +tests: +- name: Disabling Windows Local Security Authority Defences via Registry + file: endpoint/disabling_windows_local_security_authority_defences_via_registry.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/disable_lsa_protection/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_adminsdholder_acl_modified.test.yml b/tests/endpoint/windows_ad_adminsdholder_acl_modified.test.yml new file mode 100644 index 0000000000..8648fa463e --- /dev/null +++ b/tests/endpoint/windows_ad_adminsdholder_acl_modified.test.yml @@ -0,0 +1,13 @@ +name: Windows AD AdminSDHolder ACL Modified Unit Test +tests: +- name: Windows AD AdminSDHolder ACL Modified + file: endpoint/windows_ad_adminsdholder_acl_modified.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546/adminsdholder_modified/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_cross_domain_sid_history_addition.test.yml b/tests/endpoint/windows_ad_cross_domain_sid_history_addition.test.yml new file mode 100644 index 0000000000..834dc84db9 --- /dev/null +++ b/tests/endpoint/windows_ad_cross_domain_sid_history_addition.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Cross Domain SID History Addition Unit Test +tests: +- name: Windows AD Cross Domain SID History Addition + file: endpoint/windows_ad_cross_domain_sid_history_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true \ No newline at end of file diff --git a/tests/endpoint/windows_ad_domain_controller_promotion.test.yml b/tests/endpoint/windows_ad_domain_controller_promotion.test.yml new file mode 100644 index 0000000000..277852be84 --- /dev/null +++ b/tests/endpoint/windows_ad_domain_controller_promotion.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Domain Controller Promotion Unit Test +tests: +- name: Windows AD Domain Controller Promotion + file: endpoint/windows_ad_domain_controller_promotion.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/dc_promo/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_dsrm_account_changes.test.yml b/tests/endpoint/windows_ad_dsrm_account_changes.test.yml new file mode 100644 index 0000000000..4cb26cc417 --- /dev/null +++ b/tests/endpoint/windows_ad_dsrm_account_changes.test.yml @@ -0,0 +1,13 @@ +name: Windows AD DSRM Account Changes Unit Test +tests: +- name: Windows AD DSRM Account Changes + file: endpoint/windows_ad_dsrm_account_changes.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_dsrm_password_reset.test.yml b/tests/endpoint/windows_ad_dsrm_password_reset.test.yml new file mode 100644 index 0000000000..dee73e24ff --- /dev/null +++ b/tests/endpoint/windows_ad_dsrm_password_reset.test.yml @@ -0,0 +1,13 @@ +name: Windows AD DSRM Password Reset Unit Test +tests: +- name: Windows AD DSRM Password Reset + file: endpoint/windows_ad_dsrm_password_reset.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/dsrm_account/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_replication_request_initiated_by_user_account.test.yml b/tests/endpoint/windows_ad_replication_request_initiated_by_user_account.test.yml new file mode 100644 index 0000000000..d9c577236c --- /dev/null +++ b/tests/endpoint/windows_ad_replication_request_initiated_by_user_account.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Replication Request Initiated by User Account Test +tests: +- name: Windows AD Replication Request Initiated by User Account + file: endpoint/windows_ad_replication_request_initiated_by_user_account.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true \ No newline at end of file diff --git a/tests/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.test.yml b/tests/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.test.yml new file mode 100644 index 0000000000..91d9608390 --- /dev/null +++ b/tests/endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.test.yml @@ -0,0 +1,14 @@ +name: Windows AD Replication Request Initiated from Unsanctioned Location Test +tests: +- name: Windows AD Replication Request Initiated from Unsanctioned Location + file: endpoint/windows_ad_replication_request_initiated_from_unsanctioned_location.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.006/impacket/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true + diff --git a/tests/endpoint/windows_ad_same_domain_sid_history_addition.test.yml b/tests/endpoint/windows_ad_same_domain_sid_history_addition.test.yml new file mode 100644 index 0000000000..ffcc53cdcd --- /dev/null +++ b/tests/endpoint/windows_ad_same_domain_sid_history_addition.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Same Domain SID History Addition Unit Test +tests: +- name: Windows AD Same Domain SID History Addition + file: endpoint/windows_ad_same_domain_sid_history_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.test.yml b/tests/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.test.yml new file mode 100644 index 0000000000..71d06d0868 --- /dev/null +++ b/tests/endpoint/windows_ad_serviceprincipalname_added_to_domain_account.test.yml @@ -0,0 +1,13 @@ +name: Windows AD ServicePrincipalName Added To Domain Account Unit Test +tests: +- name: Windows AD ServicePrincipalName Added To Domain Account + file: endpoint/windows_ad_serviceprincipalname_added_to_domain_account.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/service_principal_name_added/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.test.yml b/tests/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.test.yml new file mode 100644 index 0000000000..0e3107989b --- /dev/null +++ b/tests/endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Short Lived Domain Account ServicePrincipalName Unit Test +tests: +- name: Windows AD Short Lived Domain Account ServicePrincipalName + file: endpoint/windows_ad_short_lived_domain_account_serviceprincipalname.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/short_lived_service_principal_name/windows-security.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.test.yml b/tests/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.test.yml new file mode 100644 index 0000000000..4c4617769f --- /dev/null +++ b/tests/endpoint/windows_ad_short_lived_domain_controller_spn_attribute.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Short Lived Domain Controller SPN Attribute Unit Test +tests: +- name: Windows AD Short Lived Domain Controller SPN Attribute + file: endpoint/windows_ad_short_lived_domain_controller_spn_attribute.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/mimikatz/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_short_lived_server_object.test.yml b/tests/endpoint/windows_ad_short_lived_server_object.test.yml new file mode 100644 index 0000000000..0593d3ac4c --- /dev/null +++ b/tests/endpoint/windows_ad_short_lived_server_object.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Short Lived Server Object Unit Test +tests: +- name: Windows Short Lived AD Server Object + file: endpoint/windows_ad_short_lived_server_object.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1207/short_lived_server_object/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/endpoint/windows_ad_sid_history_attribute_modified.test.yml b/tests/endpoint/windows_ad_sid_history_attribute_modified.test.yml new file mode 100644 index 0000000000..2809d85fdb --- /dev/null +++ b/tests/endpoint/windows_ad_sid_history_attribute_modified.test.yml @@ -0,0 +1,13 @@ +name: Windows AD SID History Attribute Modified +tests: +- name: Windows AD SID History Attribute Modified + file: endpoint/windows_ad_sid_history_attribute_modified.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/sid_history2/windows-security.log + source: XmlWinEventLog + sourcetype: XmlWinEventLog + update_timestamp: true diff --git a/tests/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.test.yml b/tests/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.test.yml new file mode 100644 index 0000000000..ea28d2a0f9 --- /dev/null +++ b/tests/experimental/endpoint/windows_ad_domain_controller_audit_policy_disabled.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Domain Controller Audit Policy Disabled Unit Test +tests: +- name: Windows AD Domain Controller Audit Policy Disabled + file: endpoint/windows_ad_domain_controller_audit_policy_disabled.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/disable_gpo/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/experimental/endpoint/windows_ad_domain_replication_acl_addition.test.yml b/tests/experimental/endpoint/windows_ad_domain_replication_acl_addition.test.yml new file mode 100644 index 0000000000..bfb0f202af --- /dev/null +++ b/tests/experimental/endpoint/windows_ad_domain_replication_acl_addition.test.yml @@ -0,0 +1,13 @@ +name: Windows AD Domain Replication ACL Addition Unit Test +tests: +- name: Windows AD Domain Replication ACL Addition + file: endpoint/windows_ad_domain_replication_acl_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/aclmodification/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true diff --git a/tests/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.test.yml b/tests/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.test.yml new file mode 100644 index 0000000000..c03cc61e4b --- /dev/null +++ b/tests/experimental/endpoint/windows_ad_privileged_account_sid_history_addition.test.yml @@ -0,0 +1,15 @@ +name: Windows AD Privileged Account SID History Addition Unit Test +tests: +- name: Windows AD Privileged Account SID History Addition + file: experimental/windows_ad_privileged_account_sid_history_addition.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: windows-security-xml.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134.005/mimikatz/windows-security-xml.log + source: XmlWinEventLog:Security + sourcetype: xmlwineventlog + update_timestamp: true + + diff --git a/tests/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml b/tests/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml new file mode 100644 index 0000000000..36f995790f --- /dev/null +++ b/tests/experimental/network/windows_ad_rogue_domain_controller_network_activity.yml @@ -0,0 +1,13 @@ +name: Windows AD Rogue Domain Controller Network Activity Unit Test +tests: +- name: Windows AD Rogue Domain Controller Network Activity + file: network/windows_ad_rogue_domain_controller_network_activity.yml + pass_condition: '| stats count | where count > 0' + earliest_time: -24h + latest_time: now + attack_data: + - file_name: zeek-dce_rpc.log + data: https://github.com/splunk/attack_data/blob/master/datasets/attack_techniques/T1207/mimikatz/zeek-dce_rpc.log + source: /opt/zeek/logs/current/dce_rpc.log + sourcetype: bro:dce_rpc:json + update_timestamp: true