From d16e2b2829b7ef2c9c63ba2b3031d438c2eb5269 Mon Sep 17 00:00:00 2001 From: root Date: Fri, 15 Oct 2021 19:26:26 +0000 Subject: [PATCH] Added detection testing service results inServicePrincipalNames Discovery with SetSPN --- ...ceprincipalnames_discovery_with_setspn.yml | 96 ++++++++++--------- 1 file changed, 53 insertions(+), 43 deletions(-) diff --git a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml index e9b159accb..fe414f47d2 100644 --- a/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml +++ b/detections/endpoint/serviceprincipalnames_discovery_with_setspn.yml @@ -6,50 +6,59 @@ author: Michael Haag, Splunk type: TTP datamodel: - Endpoint -description: 'The following analytic identifies `setspn.exe` usage related to querying the domain for Service Principle Names. typically, this is a precursor activity related to kerberoasting or the silver ticket attack. \ - +description: 'The following analytic identifies `setspn.exe` usage related to querying + the domain for Service Principle Names. typically, this is a precursor activity + related to kerberoasting or the silver ticket attack. \ + What is a ServicePrincipleName? \ - A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. This allows a client application to request that the service authenticate an account even if the client does not have the account name.\ + A service principal name (SPN) is a unique identifier of a service instance. SPNs + are used by Kerberos authentication to associate a service instance with a service + logon account. This allows a client application to request that the service authenticate + an account even if the client does not have the account name.\ Example usage includes the following \ - 1. setspn -T offense -Q */* - 1. setspn -T attackrange.local -F -Q MSSQLSvc/* - 1. setspn -Q */* > allspns.txt - 1. setspn -q \ + 1. setspn -T offense -Q */* 1. setspn -T attackrange.local -F -Q MSSQLSvc/* 1. setspn + -Q */* > allspns.txt 1. setspn -q \ Values \ - 1. -F = perform queries at the forest, rather than domain level - 1. -T = perform query on the specified domain or forest (when -F is also used) - 1. -Q = query for existence of SPN \ + 1. -F = perform queries at the forest, rather than domain level 1. -T = perform + query on the specified domain or forest (when -F is also used) 1. -Q = query for + existence of SPN \ During triage, review parallel processes for further suspicious activity.' search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) - as lastTime from datamodel=Endpoint.Processes where `process_setspn` - (Processes.process="*-t*" AND Processes.process="*-f*") OR (Processes.process="*-q*" AND Processes.process="**/**") OR (Processes.process="*-q*") OR (Processes.process="*-s*") by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name - Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)`| `serviceprincipalnames_discovery_with_setspn_filter`' -how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. -known_false_positives: False positives may be caused by Administrators resetting SPNs or querying for SPNs. Filter as needed. + as lastTime from datamodel=Endpoint.Processes where `process_setspn` (Processes.process="*-t*" + AND Processes.process="*-f*") OR (Processes.process="*-q*" AND Processes.process="**/**") + OR (Processes.process="*-q*") OR (Processes.process="*-s*") by Processes.dest Processes.user + Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `serviceprincipalnames_discovery_with_setspn_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives may be caused by Administrators resetting SPNs + or querying for SPNs. Filter as needed. references: - - https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names - - https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting - - https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html - - https://attack.mitre.org/techniques/T1558/003/ - - https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx - - https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/ - - https://blog.zsec.uk/paving-2-da-wholeset/ - - https://msitpros.com/?p=3113 - - https://adsecurity.org/?p=3466 +- https://docs.microsoft.com/en-us/windows/win32/ad/service-principal-names +- https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/t1208-kerberoasting +- https://strontic.github.io/xcyclopedia/library/setspn.exe-5C184D581524245DAD7A0A02B51FD2C2.html +- https://attack.mitre.org/techniques/T1558/003/ +- https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spn-setspn-syntax.aspx +- https://www.harmj0y.net/blog/powershell/kerberoasting-without-mimikatz/ +- https://blog.zsec.uk/paving-2-da-wholeset/ +- https://msitpros.com/?p=3113 +- https://adsecurity.org/?p=3466 tags: analytic_story: - Active Directory Discovery - Lateral Movement - dataset: [] + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1558.003/atomic_red_team/windows-sysmon_setspn.log kill_chain_phases: - Lateral Movement mitre_attack_id: @@ -59,27 +68,27 @@ tags: - Splunk Enterprise Security - Splunk Cloud required_fields: - - _time - - Processes.dest - - Processes.user - - Processes.parent_process_name #parent process name - - Processes.parent_process #parent cmdline - - Processes.original_file_name - - Processes.process_name #process name - - Processes.process #process cmdline - - Processes.process_id - - Processes.parent_process_path - - Processes.process_path - - Processes.parent_process_id + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id security_domain: endpoint impact: 80 confidence: 100 - # (impact * confidence)/100 risk_score: 80 context: - Source:Endpoint - Stage:Credential Access - message: An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest$ by user $user$ attempting to identify service principle names. + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$ by user $user$ attempting to identify service principle names. observable: - name: user type: User @@ -96,4 +105,5 @@ tags: - name: process_name type: Process role: - - Child Process \ No newline at end of file + - Child Process + automated_detection_testing: passed