diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 0d15635152..71e463fbf9 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -44,6 +44,7 @@ tags: of $expected_upper_threshold$ with the following command $command$. mitre_attack_id: - T1078.004 + - T1078 nist: - DE.DP - DE.CM diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index 2b216b747e..1228ec4926 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -49,6 +49,7 @@ tags: command $command$. mitre_attack_id: - T1078.004 + - T1078 nist: - DE.DP - DE.CM diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml index eeda62b531..931bf81982 100644 --- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml @@ -46,6 +46,7 @@ tags: in their account mitre_attack_id: - T1078.004 + - T1078 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml index ed140d24b7..5c2276390f 100644 --- a/detections/cloud/aws_createaccesskey.yml +++ b/detections/cloud/aws_createaccesskey.yml @@ -43,6 +43,7 @@ tags: from this IP $src$ mitre_attack_id: - T1136.003 + - T1136 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml index b537158602..5a203a77d8 100644 --- a/detections/cloud/aws_createloginprofile.yml +++ b/detections/cloud/aws_createloginprofile.yml @@ -46,6 +46,7 @@ tags: and did a console login from this IP $src_ip$ mitre_attack_id: - T1136.003 + - T1136 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_ecr_container_scanning_findings_high.yml b/detections/cloud/aws_ecr_container_scanning_findings_high.yml index e7eca8106c..9a9eeb3114 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_high.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_high.yml @@ -37,6 +37,7 @@ tags: message: Vulnerabilities with severity high found in image $image$ mitre_attack_id: - T1204.003 + - T1204 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml index f6c36e1a8a..2baabc0834 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_low_informational_unknown.yml @@ -36,6 +36,7 @@ tags: message: Vulnerabilities with severity high found in repository $repositoryName$ mitre_attack_id: - T1204.003 + - T1204 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml index eda8bdae60..755368af77 100644 --- a/detections/cloud/aws_ecr_container_scanning_findings_medium.yml +++ b/detections/cloud/aws_ecr_container_scanning_findings_medium.yml @@ -35,6 +35,7 @@ tags: message: Vulnerabilities with severity high found in image $image$ mitre_attack_id: - T1204.003 + - T1204 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml index 2d193b4d16..e64f1de95b 100644 --- a/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml +++ b/detections/cloud/aws_ecr_container_upload_outside_business_hours.yml @@ -33,6 +33,7 @@ tags: message: Container uploaded outside business hours from $user$ mitre_attack_id: - T1204.003 + - T1204 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_ecr_container_upload_unknown_user.yml b/detections/cloud/aws_ecr_container_upload_unknown_user.yml index 0e15c5211e..82d4fd850e 100644 --- a/detections/cloud/aws_ecr_container_upload_unknown_user.yml +++ b/detections/cloud/aws_ecr_container_upload_unknown_user.yml @@ -33,6 +33,7 @@ tags: message: Container uploaded from unknown user $user$ mitre_attack_id: - T1204.003 + - T1204 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_iam_successful_group_deletion.yml b/detections/cloud/aws_iam_successful_group_deletion.yml index 6efc567d1d..c39a47fc4d 100644 --- a/detections/cloud/aws_iam_successful_group_deletion.yml +++ b/detections/cloud/aws_iam_successful_group_deletion.yml @@ -42,6 +42,7 @@ tags: mitre_attack_id: - T1069.003 - T1098 + - T1069 observable: - name: src type: IP Address diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml index a7059316a2..028c55621a 100644 --- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml @@ -46,6 +46,7 @@ tags: CIDR $requestParameters.cidrBlock$ mitre_attack_id: - T1562.007 + - T1562 nist: - DE.DP - DE.AE diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 55634ba086..5a09c419bf 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -41,6 +41,7 @@ tags: $eventName$), such that the instance is accessible from anywhere mitre_attack_id: - T1562.007 + - T1562 nist: - DE.DP - DE.AE diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml index 546333f7e9..6f90e57391 100644 --- a/detections/cloud/aws_setdefaultpolicyversion.yml +++ b/detections/cloud/aws_setdefaultpolicyversion.yml @@ -45,6 +45,7 @@ tags: event $eventName$ for updating the the default policy version mitre_attack_id: - T1078.004 + - T1078 nist: - PR.DS - PR.AC diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index 2d6d80437e..0c7fd9c7b2 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -39,6 +39,7 @@ tags: user $user_arn$ more access privilleges mitre_attack_id: - T1136.003 + - T1136 nist: - PR.DS - PR.AC diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index f70c6e911a..43c8ea2de0 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -44,6 +44,7 @@ tags: message: User $user$ is creating a new instance $dest$ for the first time mitre_attack_id: - T1078.004 + - T1078 nist: - ID.AM observable: diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index 185d54b516..f05c111905 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -44,6 +44,7 @@ tags: message: User $user$ is modifying an instance $dest$ for the first time. mitre_attack_id: - T1078.004 + - T1078 nist: - ID.AM observable: diff --git a/detections/cloud/correlation_by_repository_and_risk.yml b/detections/cloud/correlation_by_repository_and_risk.yml index 78763720ca..8cae1eaf2f 100644 --- a/detections/cloud/correlation_by_repository_and_risk.yml +++ b/detections/cloud/correlation_by_repository_and_risk.yml @@ -27,6 +27,7 @@ tags: message: Correlation triggered for user $user$ mitre_attack_id: - T1204.003 + - T1204 nist: - PR.DS - PR.AC diff --git a/detections/cloud/correlation_by_user_and_risk.yml b/detections/cloud/correlation_by_user_and_risk.yml index 6cbb1f0832..220dcb76c1 100644 --- a/detections/cloud/correlation_by_user_and_risk.yml +++ b/detections/cloud/correlation_by_user_and_risk.yml @@ -27,6 +27,7 @@ tags: message: Correlation triggered for user $user$ mitre_attack_id: - T1204.003 + - T1204 nist: - PR.DS - PR.AC diff --git a/detections/cloud/github_commit_changes_in_master.yml b/detections/cloud/github_commit_changes_in_master.yml index 8b6d910d1e..9475fcad55 100644 --- a/detections/cloud/github_commit_changes_in_master.yml +++ b/detections/cloud/github_commit_changes_in_master.yml @@ -23,7 +23,7 @@ references: - https://www.redhat.com/en/topics/devops/what-is-devsecops tags: analytic_story: - - DevSecOps + - Dev Sec Ops automated_detection_testing: passed confidence: 30 context: diff --git a/detections/cloud/github_commit_in_develop.yml b/detections/cloud/github_commit_in_develop.yml index 85c5cf21f8..e069f8de60 100644 --- a/detections/cloud/github_commit_in_develop.yml +++ b/detections/cloud/github_commit_in_develop.yml @@ -22,7 +22,7 @@ references: - https://www.redhat.com/en/topics/devops/what-is-devsecops tags: analytic_story: - - DevSecOps + - Dev Sec Ops automated_detection_testing: passed confidence: 30 context: diff --git a/detections/cloud/github_dependabot_alert.yml b/detections/cloud/github_dependabot_alert.yml index 4294037188..0ac8b391b0 100644 --- a/detections/cloud/github_dependabot_alert.yml +++ b/detections/cloud/github_dependabot_alert.yml @@ -33,6 +33,7 @@ tags: message: Vulnerabilities found in packages used by GitHub repository $repository$ mitre_attack_id: - T1195.001 + - T1195 nist: - PR.DS - PR.AC diff --git a/detections/cloud/github_pull_request_from_unknown_user.yml b/detections/cloud/github_pull_request_from_unknown_user.yml index 3f4235831b..82025ef1a6 100644 --- a/detections/cloud/github_pull_request_from_unknown_user.yml +++ b/detections/cloud/github_pull_request_from_unknown_user.yml @@ -33,6 +33,7 @@ tags: message: Vulnerabilities found in packages used by GitHub repository $repository$ mitre_attack_id: - T1195.001 + - T1195 nist: - PR.DS - PR.AC diff --git a/detections/cloud/gsuite_drive_share_in_external_email.yml b/detections/cloud/gsuite_drive_share_in_external_email.yml index b451a2c38f..cd17a1880e 100644 --- a/detections/cloud/gsuite_drive_share_in_external_email.yml +++ b/detections/cloud/gsuite_drive_share_in_external_email.yml @@ -19,14 +19,14 @@ search: '`gsuite_drive` NOT (email IN("", "null")) | rex field=parameters.owner | `gsuite_drive_share_in_external_email_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file - extension, source email, destination email, num of attachment and etc. + extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. known_false_positives: network admin or normal user may share files to customer and external team. references: - https://www.redhat.com/en/topics/devops/what-is-devsecops tags: analytic_story: - - DevSecOps + - Dev Sec Ops confidence: 90 context: - Source:Endpoint @@ -41,11 +41,12 @@ tags: message: suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$ mitre_attack_id: - T1567.002 + - T1567 observable: - name: parameters.owner type: User role: - - attacker + - Attacker - name: email type: User role: @@ -66,3 +67,4 @@ tags: - parameters.doc_type risk_score: 72 security_domain: endpoint + diff --git a/detections/cloud/gsuite_email_suspicious_attachment.yml b/detections/cloud/gsuite_email_suspicious_attachment.yml index 664b291d70..9c9133fe0b 100644 --- a/detections/cloud/gsuite_email_suspicious_attachment.yml +++ b/detections/cloud/gsuite_email_suspicious_attachment.yml @@ -28,7 +28,7 @@ references: - https://www.redhat.com/en/topics/devops/what-is-devsecops tags: analytic_story: - - DevSecOps + - Dev Sec Ops confidence: 70 context: - Source:Endpoint @@ -41,6 +41,7 @@ tags: message: suspicious email from $source.address$ to $destination{}.address$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: source.address type: User diff --git a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml index be34394965..1472fa6c77 100644 --- a/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml +++ b/detections/cloud/gsuite_email_suspicious_subject_with_attachment.yml @@ -35,7 +35,7 @@ references: - https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-top-spear-phishing-words.pdf tags: analytic_story: - - DevSecOps + - Dev Sec Ops automated_detection_testing: passed confidence: 50 context: @@ -49,6 +49,7 @@ tags: message: suspicious email from $source.address$ to $destination{}.address$ mitre_attack_id: - T1566.001 + - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml index aaf6b6cf5f..bbfe333ea6 100644 --- a/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml +++ b/detections/cloud/gsuite_email_with_known_abuse_web_service_link.yml @@ -26,7 +26,7 @@ references: - https://news.sophos.com/en-us/2021/07/22/malware-increasingly-targets-discord-for-abuse/ tags: analytic_story: - - DevSecOps + - Dev Sec Ops automated_detection_testing: passed confidence: 50 context: @@ -40,6 +40,7 @@ tags: message: suspicious email from $source.address$ to $destination{}.address$ mitre_attack_id: - T1566.001 + - T1566 product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml index d4e3964783..c8c2b596d6 100644 --- a/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml +++ b/detections/cloud/gsuite_outbound_email_with_attachment_to_external_domain.yml @@ -27,7 +27,7 @@ references: - https://www.redhat.com/en/topics/devops/what-is-devsecops tags: analytic_story: - - DevSecOps + - Dev Sec Ops confidence: 30 context: - Source:Endpoint @@ -40,6 +40,7 @@ tags: message: suspicious email from $source.address$ to $destination{}.address$ mitre_attack_id: - T1048.003 + - T1048 observable: - name: source.address type: User diff --git a/detections/cloud/gsuite_suspicious_shared_file_name.yml b/detections/cloud/gsuite_suspicious_shared_file_name.yml index 65c240346c..d55a4bab94 100644 --- a/detections/cloud/gsuite_suspicious_shared_file_name.yml +++ b/detections/cloud/gsuite_suspicious_shared_file_name.yml @@ -24,7 +24,7 @@ search: '`gsuite_drive` parameters.owner_is_team_drive=false "parameters.doc_tit | `gsuite_suspicious_shared_file_name_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs related to gsuite having the file attachment metadata like file type, file - extension, source email, destination email, num of attachment and etc. + extension, source email, destination email, num of attachment and etc. In order for the search to work for your environment, please edit the query to use your company specific email domain instead of `internal_test_email.com`. known_false_positives: normal user or normal transaction may contain the subject and file type attachment that this detection try to search references: @@ -32,7 +32,7 @@ references: - https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-top-spear-phishing-words.pdf tags: analytic_story: - - DevSecOps + - Dev Sec Ops automated_detection_testing: passed confidence: 70 context: @@ -46,6 +46,7 @@ tags: message: suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$ mitre_attack_id: - T1566.001 + - T1566 observable: - name: parameters.owner type: User diff --git a/detections/cloud/o365_add_app_role_assignment_grant_user.yml b/detections/cloud/o365_add_app_role_assignment_grant_user.yml index 577c75383a..731f801395 100644 --- a/detections/cloud/o365_add_app_role_assignment_grant_user.yml +++ b/detections/cloud/o365_add_app_role_assignment_grant_user.yml @@ -41,6 +41,7 @@ tags: Address $ActorIpAddress$ mitre_attack_id: - T1136.003 + - T1136 observable: - name: ActorIpAddress type: IP Address diff --git a/detections/cloud/o365_added_service_principal.yml b/detections/cloud/o365_added_service_principal.yml index ea17167487..6bcfb6259b 100644 --- a/detections/cloud/o365_added_service_principal.yml +++ b/detections/cloud/o365_added_service_principal.yml @@ -44,6 +44,7 @@ tags: service principal credentials from IP Address $ActorIpAddress$ mitre_attack_id: - T1136.003 + - T1136 observable: - name: ActorIpAddress type: IP Address diff --git a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml index 1fc40093a1..4a9a8ef9ea 100644 --- a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml +++ b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml @@ -45,6 +45,7 @@ tags: list of trusted IPs to bypass MFA mitre_attack_id: - T1562.007 + - T1562 observable: - name: ip_addresses_new_added type: IP Address diff --git a/detections/cloud/o365_new_federated_domain_added.yml b/detections/cloud/o365_new_federated_domain_added.yml index 5984dfc60d..7a416e6f60 100644 --- a/detections/cloud/o365_new_federated_domain_added.yml +++ b/detections/cloud/o365_new_federated_domain_added.yml @@ -44,6 +44,7 @@ tags: $OrganizationName$ mitre_attack_id: - T1136.003 + - T1136 observable: - name: OrganizationName type: Other diff --git a/detections/cloud/o365_suspicious_admin_email_forwarding.yml b/detections/cloud/o365_suspicious_admin_email_forwarding.yml index 82746f0989..cbb85e57e6 100644 --- a/detections/cloud/o365_suspicious_admin_email_forwarding.yml +++ b/detections/cloud/o365_suspicious_admin_email_forwarding.yml @@ -39,6 +39,7 @@ tags: the same destination $ForwardingAddress$ mitre_attack_id: - T1114.003 + - T1114 nist: - DE.DP - DE.AE diff --git a/detections/cloud/o365_suspicious_rights_delegation.yml b/detections/cloud/o365_suspicious_rights_delegation.yml index 06d05f296e..be8f002199 100644 --- a/detections/cloud/o365_suspicious_rights_delegation.yml +++ b/detections/cloud/o365_suspicious_rights_delegation.yml @@ -38,6 +38,7 @@ tags: that allow access to sensitive mitre_attack_id: - T1114.002 + - T1114 nist: - DE.DP - DE.AE diff --git a/detections/cloud/o365_suspicious_user_email_forwarding.yml b/detections/cloud/o365_suspicious_user_email_forwarding.yml index 9a7276d8b6..7644ef34f2 100644 --- a/detections/cloud/o365_suspicious_user_email_forwarding.yml +++ b/detections/cloud/o365_suspicious_user_email_forwarding.yml @@ -39,6 +39,7 @@ tags: a forwarding rule to same destination $ForwardingSmtpAddress$ mitre_attack_id: - T1114.003 + - T1114 nist: - DE.DP - DE.AE diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml new file mode 100644 index 0000000000..11492c7e1a --- /dev/null +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -0,0 +1,70 @@ +name: Active Setup Registry Autostart +id: f64579c0-203f-11ec-abcc-acde48001122 +version: 1 +date: '2021-09-28' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious modification of the active setup + registry for persistence and privilege escalation. This technique was seen in several + malware (poisonIvy), adware and APT to gain persistence to the compromised machine + upon boot up. This TTP is a good indicator to further check the process id that + do the modification since modification of this registry is not commonly done. check + the legitimacy of the file and process involve in this rules to check if it is a + valid setup installer that creating or modifying this registry. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_value_name + = "StubPath" Registry.registry_key_name = "*\\SOFTWARE\\Microsoft\\Active Setup\\Installed + Components*" by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name + Registry.registry_value_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` + | `drop_dm_object_name(Registry)` | `active_setup_registry_autostart_filter`' +how_to_implement: To successfully implement this search, you must be ingesting + data that records registry activity from your hosts to populate the endpoint data + model in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Active setup installer may add or modify this registry. +references: +- https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor%3aWin32%2fPoisonivy.E +- https://attack.mitre.org/techniques/T1547/014/ +tags: + analytic_story: + - Windows Persistence Techniques + - Windows Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1547.014 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + security_domain: endpoint + impact: 80 + confidence: 80 + risk_score: 64 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml new file mode 100644 index 0000000000..44cab51f50 --- /dev/null +++ b/detections/endpoint/change_default_file_association.yml @@ -0,0 +1,67 @@ +name: Change Default File Association +id: 462d17d8-1f71-11ec-ad07-acde48001122 +version: 1 +date: '2021-09-27' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is developed to detect suspicious registry modification + to change the default file association of windows to malicious payload. This techninique + was seen in some APT where it modify the default process to run file association, + like .txt to notepad.exe. Instead notepad.exe it will point to a Script or other + payload that will load malicious command to the compromised host. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path + ="*\\shell\\open\\command\\*" Registry.registry_path = "*HKCR\\*" by Registry.dest Registry.user + Registry.registry_path Registry.registry_key_name Registry.registry_value_name | + `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` + | `change_default_file_association_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: unknown +references: +- https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features +tags: + analytic_story: + - Windows Persistence Techniques + - Windows Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1546.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/disable_security_logs_using_minint_registry.yml b/detections/endpoint/disable_security_logs_using_minint_registry.yml new file mode 100644 index 0000000000..b73414b69a --- /dev/null +++ b/detections/endpoint/disable_security_logs_using_minint_registry.yml @@ -0,0 +1,65 @@ +name: Disable Security Logs Using MiniNt Registry +id: 39ebdc68-25b9-11ec-aec7-acde48001122 +version: 1 +date: '2021-10-05' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious registry modification to disable + security audit logs. This technique was shared by a researcher to disable Security + logs of windows by adding this registry. The Windows will think it is WinPE and + will not log any event to the Security Log +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\Control\\MiniNt\\*" + by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name + Registry.registry_path Registry.registry_value_data | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `disable_security_logs_using_minint_registry_filter`' +how_to_implement: To successfully implement this search, you must be ingesting + data that records registry activity from your hosts to populate the endpoint data + model in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: Unknown. +references: +- https://twitter.com/0gtweet/status/1182516740955226112 +tags: + analytic_story: + - Windows Defense Evasion Tactics + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1112 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_value_name + - Registry.registry_key_name + - Registry.registry_path + - Registry.registry_value_data + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/disable_uac_remote_restriction.yml b/detections/endpoint/disable_uac_remote_restriction.yml new file mode 100644 index 0000000000..80d564165f --- /dev/null +++ b/detections/endpoint/disable_uac_remote_restriction.yml @@ -0,0 +1,69 @@ +name: Disable UAC Remote Restriction +id: 9928b732-210e-11ec-b65e-acde48001122 +version: 1 +date: '2021-09-29' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious modification of registry to disable + UAC remote restriction. This technique was well documented in Microsoft page where + attacker may modify this registry value to bypassed UAC feature of windows host. + This is a good indicator that some tries to bypassed UAC to suspicious process or + gain privilege escalation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path + ="*\\CurrentVersion\\Policies\\System*" Registry.registry_value_name="LocalAccountTokenFilterPolicy" + Registry.registry_value_data="0x00000001" by Registry.dest Registry.user Registry.registry_path + Registry.registry_key_name Registry.registry_value_name Registry.registry_value_data + | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` + | `disable_uac_remote_restriction_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: admin may set this policy for non-critical machine. +references: +- https://docs.microsoft.com/en-us/troubleshoot/windows-server/windows-security/user-account-control-and-remote-restriction +tags: + analytic_story: + - Windows Defense Evasion Tactics + - Suspicious Windows Registry Activities + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1548.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + - Registry.registry_value_data + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml new file mode 100644 index 0000000000..9f23806bae --- /dev/null +++ b/detections/endpoint/enable_wdigest_uselogoncredential_registry.yml @@ -0,0 +1,68 @@ +name: Enable WDigest UseLogonCredential Registry +id: 0c7d8ffe-25b1-11ec-9f39-acde48001122 +version: 1 +date: '2021-10-05' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious registry modification to enable + plain text credential feature of windows. This technique was used by several malware + and also by mimikatz to be able to dumpe the a plain text credential to the compromised + or target host. This TTP is really a good indicator that someone wants to dump the + crendential of the host so it must be a good pivot for credential dumping techniques. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*\\System\\CurrentControlSet\\Control\\SecurityProviders\\WDigest\\*" + Registry.registry_value_name = "UseLogonCredential" Registry.registry_value_data + = 0x00000001 by Registry.dest Registry.user Registry.registry_value_name Registry.registry_key_name + Registry.registry_path Registry.registry_value_data | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `enable_wdigest_uselogoncredential_registry_filter`' +how_to_implement: To successfully implement this search, you must be ingesting + data that records registry activity from your hosts to populate the endpoint data + model in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: unknown +references: +- https://www.csoonline.com/article/3438824/how-to-detect-and-halt-credential-theft-via-windows-wdigest.html +tags: + analytic_story: + - Credential Dumping + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1112 + - T1003 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_value_name + - Registry.registry_key_name + - Registry.registry_path + - Registry.registry_value_data + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Credential Access + message: wdigest registry $registry_path$ was modified in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml new file mode 100644 index 0000000000..c129367c35 --- /dev/null +++ b/detections/endpoint/etw_registry_disabled.yml @@ -0,0 +1,67 @@ +name: ETW Registry Disabled +id: 8ed523ac-276b-11ec-ac39-acde48001122 +version: 1 +date: '2021-10-07' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a registry modification to disable ETW feature + of windows. This technique is to evade EDR appliance to evade detections and hide + its execution from audit logs. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\SOFTWARE\\Microsoft\\.NETFramework*") + Registry.registry_value_name = ETWEnabled Registry.registry_value_data=0x00000000 + by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name + Registry.registry_value_name Registry.registry_value_data | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `etw_registry_disabled_filter`' +how_to_implement: To successfully implement this search, you must be ingesting + data that records registry activity from your hosts to populate the endpoint data + model in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: unknown +references: +- https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3 +tags: + analytic_story: + - Windows Persistence Techniques + - Windows Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1562.006 + - T1127 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + - Registry.registry_value_data + security_domain: endpoint + impact: 90 + confidence: 100 + risk_score: 90 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml new file mode 100644 index 0000000000..e881970354 --- /dev/null +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -0,0 +1,65 @@ +name: Logon Script Event Trigger Execution +id: 4c38c264-1f74-11ec-b5fa-acde48001122 +version: 1 +date: '2021-09-27' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This search is to detect a suspicious modification of registry entry + to persist and gain privilege escalation upon booting up of compromised host. This + technique was seen in several APT and malware where it modify UserInitMprLogonScript + registry entry to its malicious payload to be executed upon boot up of the machine. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path + IN ("*\\Environment\\UserInitMprLogonScript") by Registry.dest Registry.user Registry.registry_path + Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `logon_script_event_trigger_execution_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: unknown +references: +- https://attack.mitre.org/techniques/T1037/001 +tags: + analytic_story: + - Windows Persistence Techniques + - Windows Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1037.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/malicious_inprocserver32_modification.yml b/detections/endpoint/malicious_inprocserver32_modification.yml new file mode 100644 index 0000000000..7e935088fb --- /dev/null +++ b/detections/endpoint/malicious_inprocserver32_modification.yml @@ -0,0 +1,86 @@ +name: Malicious InProcServer32 Modification +id: 127c8d08-25ff-11ec-9223-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies a process modifying the registry with + a known malicious CLSID under InProcServer32. Most COM classes are registered with + the operating system and are identified by a GUID that represents the Class Identifier + (CLSID) within the registry (usually under HKLM\\Software\\Classes\\CLSID or HKCU\\Software\\Classes\\CLSID). Behind + the implementation of a COM class is the server (some binary) that is referenced + within registry keys under the CLSID. The LocalServer32 key represents a path to + an executable (exe) implementation, and the InprocServer32 key represents a path + to a dynamic link library (DLL) implementation (Bohops). During triage, review parallel + processes for suspicious activity. Pivot on the process GUID to see the full timeline + of events. Analyze the value and look for file modifications. Being this is looking + for inprocserver32, a DLL found in the value will most likely be loaded by a parallel + process. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid + Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats + `security_content_summariesonly` count FROM datamodel=Endpoint.Registry where Registry.registry_path= + "*\\CLSID\\{89565275-A714-4a43-912E-978B935EDCCC}\\InProcServer32\\(Default)" by + Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest + Registry.process_guid Registry.user | `drop_dm_object_name(Registry)` | fields _time + dest registry_path registry_key_name registry_value_name process_name process_path + process process_guid user] | stats count min(_time) as firstTime max(_time) as lastTime + by dest, process_name registry_path registry_key_name registry_value_name user | + `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `malicious_inprocserver32_modification_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Registry` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited, filter as needed. In our + test case, Remcos used regsvr32.exe to modify the registry. It may be required, + dependent upon the EDR tool producing registry events, to remove (Default) from + the command-line. +references: +- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Suspicious Regsvr32 Activity + - Remcos + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.010 + - T1112 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - process_name + - registry_path + - registry_key_name + - registry_value_name + - user + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: The $process_name$ was identified on endpoint $dest$ modifying the registry + with a known malicious clsid under InProcServer32. + observable: + - name: dest + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + automated_detection_testing: passed diff --git a/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml new file mode 100644 index 0000000000..d0687e4c57 --- /dev/null +++ b/detections/endpoint/msbuild_suspicious_spawned_by_script_process.yml @@ -0,0 +1,65 @@ +name: MSBuild Suspicious Spawned By Script Process +id: 213b3148-24ea-11ec-93a2-acde48001122 +version: 1 +date: '2021-10-04' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious child process of MSBuild + spawned by Windows Script Host - cscript or wscript. + This behavior or event are commonly seen and used by malware or adversaries + to execute malicious msbuild process using malicious script in the compromised host. + During triage, review parallel processes and identify any file modifications. MSBuild + may load a script from the same path without having command-line arguments. +search: '| tstats `security_content_summariesonly` count values(Processes.process_name) + as process_name values(Processes.process) as process min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name + IN ("wscript.exe", "cscript.exe") AND `process_msbuild` by Processes.dest Processes.parent_process + Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `msbuild_suspicious_spawned_by_script_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: False positives should be limited as developers do not spawn MSBuild via a WSH. +references: +- https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# +tags: + analytic_story: + - Trusted Developer Utilities Proxy Execution MSBuild + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1127.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.parent_process + - Processes.parent_process_name + - Processes.process_name + - Processes.original_file_name + - Processes.user + security_domain: endpoint + impact: 70 + confidence: 70 + risk_score: 49 + context: + - Stage:Execution + - Stage:Defense Evasion + message: Msbuild.exe process spawned by $parent_process_name$ on $dest$ executed + by $user$ + observable: + - name: dest + type: Endpoint + role: + - Victim + - name: User + type: User + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/process_writing_dynamicwrapperx.yml b/detections/endpoint/process_writing_dynamicwrapperx.yml new file mode 100644 index 0000000000..bea147733f --- /dev/null +++ b/detections/endpoint/process_writing_dynamicwrapperx.yml @@ -0,0 +1,86 @@ +name: Process Writing DynamicWrapperX +id: b0a078e4-2601-11ec-9aec-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: Hunting +datamodel: +- Endpoint +description: DynamicWrapperX is an ActiveX component that can be used in a script + to call Windows API functions, but it requires the dynwrapx.dll to be installed + and registered. With that, a binary writing dynwrapx.dll to disk and registering + it into the registry is highly suspect. Why is it needed? In most malicious instances, + it will be written to disk at a non-standard location. During triage, review parallel + processes and pivot on the process_guid. Review the registry for any suspicious + modifications meant to load dynwrapx.dll. Identify any suspicious module loads of + dynwrapx.dll. This will identify the process that will invoke vbs/wscript/cscript. +search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes + by _time Processes.process_id Processes.process_name Processes.dest Processes.process_guid + Processes.user | `drop_dm_object_name(Processes)` | join process_guid [| tstats + `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where + Filesystem.file_name="dynwrapx.dll" by _time Filesystem.dest Filesystem.file_create_time + Filesystem.file_name Filesystem.file_path Filesystem.process_guid Filesystem.user + | `drop_dm_object_name(Filesystem)` | fields _time process_guid file_path file_name + file_create_time user dest process_name] | stats count min(_time) as firstTime max(_time) + as lastTime by dest process_name process_guid file_name file_path file_create_time + user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `process_writing_dynamicwrapperx_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` and `Filesystem` + node. In addition, confirm the latest CIM App 4.20 or higher is installed and the + latest TA for the endpoint product. +known_false_positives: False positives should be limited, however it is possible to + filter by Processes.process_name and specific processes (ex. wscript.exe). Filter + as needed. This may need modification based on EDR telemetry and how it brings in registry data. For example, removal of (Default). +references: +- https://blog.f-secure.com/hunting-for-koadic-a-com-based-rootkit/ +- https://www.script-coding.com/dynwrapx_eng.html +- https://bohops.com/2018/06/28/abusing-com-registry-structure-clsid-localserver32-inprocserver32/ +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Remcos + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1059 + - T1559.001 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - dest + - process_name + - process_guid + - file_name + - file_path + - file_create_time user + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $process_name$ was identified on endpoint $dest$ downloading + the DynamicWrapperX dll. + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: process_name + type: Process + role: + - Child Process + automated_detection_testing: passed diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index 36b0346da1..33f290cdd1 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -11,7 +11,8 @@ description: The search looks for modifications to registry keys that can be use search: '| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*\\currentversion\\run* - OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* + OR Registry.registry_path=*\\currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Shell* + OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Notify* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*\\CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*\\currentversion\\policies\\explorer\\run* OR Registry.registry_path=*\\currentversion\\runservices* OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\* OR (Registry.registry_path="*Microsoft\\Windows diff --git a/detections/endpoint/regsvr32_silent_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_param_dll_loading.yml new file mode 100644 index 0000000000..d27c7425aa --- /dev/null +++ b/detections/endpoint/regsvr32_silent_param_dll_loading.yml @@ -0,0 +1,73 @@ +name: Regsvr32 Silent Param Dll Loading +id: f421c250-24e7-11ec-bc43-acde48001122 +version: 1 +date: '2021-10-04' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a loading of dll using regsvr32 application + with silent parameter and dllinstall execution. This technique was seen in several + RAT malware like remcos, njrat and APT's to load their malicious dll in the compromised + machine. This TTP may executed by normal 3rd party application so it is better to + pivot the parent process, parent commandline and commandline of the file that execute + this regsvr32. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name = regsvr32.exe + Processes.process="*/i*" Processes.process="*/s*" by Processes.dest Processes.parent_process + Processes.process Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `regsvr32_silent_param_dll_loading_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: Other third part application may used this parameter but not + so common in base windows environment. +references: +- https://app.any.run/tasks/dc93ee63-050c-4ff8-b07e-8277af9ab939/# +- https://attack.mitre.org/techniques/T1218/010/ +tags: + analytic_story: + - Suspicious Regsvr32 Activity + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.010 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 60 + confidence: 60 + risk_score: 36 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: regsvr32 process with $process$ commandline in $dest$ + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/rundll32_shimcache_flush.yml b/detections/endpoint/rundll32_shimcache_flush.yml new file mode 100644 index 0000000000..d4e0993b51 --- /dev/null +++ b/detections/endpoint/rundll32_shimcache_flush.yml @@ -0,0 +1,67 @@ +name: Rundll32 Shimcache Flush +id: a913718a-25b6-11ec-96d3-acde48001122 +version: 1 +date: '2021-10-05' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious rundll32 commandline to clear + shim cache. This technique is a anti-forensic technique to clear the cache taht + are one important artifacts in terms of digital forensic during attacks or incident. + This TTP is a good indicator that someone tries to evade some tools and clear foothold + on the machine. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where `process_rundll32` AND Processes.process + = "*apphelp.dll,ShimFlushCache*" by Processes.dest Processes.user Processes.parent_process_name + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id Processes.original_file_name + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `rundll32_shimcache_flush_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: unknown +references: +- https://blueteamops.medium.com/shimcache-flush-89daff28d15e +tags: + analytic_story: + - Unusual Processes + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1112 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Stage:Execution + - Stage:Defense Evasion + message: rundll32 process execute $process$ to clear shim cache in $dest$ + observable: + - name: dest + type: Endpoint + role: + - Victim + - name: User + type: User + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml new file mode 100644 index 0000000000..00b8914da3 --- /dev/null +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -0,0 +1,68 @@ +name: Screensaver Event Trigger Execution +id: 58cea3ec-1f6d-11ec-8560-acde48001122 +version: 1 +date: '2021-09-27' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is developed to detect possible event trigger execution + through screensaver registry entry modification for persistence or privilege escalation. + This technique was seen in several APT and malware where they put the malicious + payload path to the SCRNSAVE.EXE registry key to redirect the execution to their + malicious payload path. This TTP is a good indicator that some attacker may modify + this entry for their persistence and privilege escalation. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*\\Control + Panel\\Desktop\\SCRNSAVE.EXE*") by Registry.dest Registry.user Registry.registry_path + Registry.registry_key_name Registry.registry_value_name | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `screensaver_event_trigger_execution_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: unknown +references: +- https://attack.mitre.org/techniques/T1546/002/ +- https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver +tags: + analytic_story: + - Windows Persistence Techniques + - Windows Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1546.002 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + security_domain: endpoint + impact: 80 + confidence: 90 + risk_score: 72 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/sdelete_application_execution.yml b/detections/endpoint/sdelete_application_execution.yml new file mode 100644 index 0000000000..0ded4ef8bc --- /dev/null +++ b/detections/endpoint/sdelete_application_execution.yml @@ -0,0 +1,70 @@ +name: Sdelete Application Execution +id: 31702fc0-2682-11ec-85c3-acde48001122 +version: 1 +date: '2021-10-06' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect the execution of sdelete.exe application sysinternal + tools. This tool is one of the most use tool of malware and adversaries to remove + or clear their tracks and artifact in the targetted host. This tool is designed + to delete securely a file in file system that remove the forensic evidence on the + machine. A good TTP query to check why user execute this application which is not + a common practice. +search: '| tstats `security_content_summariesonly` values(Processes.process) as process + values(Processes.parent_process) as parent_process values(Processes.process_id) + as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where `process_sdelete` by Processes.process_name Processes.original_file_name + Processes.dest Processes.user Processes.parent_process_name Processes.parent_process + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `sdelete_application_execution_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: user may execute and use this application +references: +- https://app.any.run/tasks/956f50be-2c13-465a-ac00-6224c14c5f89/ +tags: + analytic_story: + - Masquerading - Rename System Utilities + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1485 + - T1070.004 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 70 + confidence: 70 + risk_score: 49 + context: + - Source:Endpoint + - Stage:Execution + message: sdelete process $process_name$ executed in $dest$ + observable: + - name: dest + type: Endpoint + role: + - Victim + - name: user + type: User + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_copy_on_system32.yml b/detections/endpoint/suspicious_copy_on_system32.yml new file mode 100644 index 0000000000..3eb05fde0f --- /dev/null +++ b/detections/endpoint/suspicious_copy_on_system32.yml @@ -0,0 +1,68 @@ +name: Suspicious Copy on System32 +id: ce633e56-25b2-11ec-9e76-acde48001122 +version: 1 +date: '2021-10-05' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious copy of file from systemroot + folder of the windows OS. This technique is commonly used by APT or other malware + as part of execution (LOLBIN) to run its malicious code using the available legitimate + tool in OS. this type of event may seen or may execute of normal user in some instance + but this is really a anomaly that needs to be check within the network. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name + IN("cmd.exe", "powershell*","pwsh.exe", "sqlps.exe", "sqltoolsps.exe", "powershell_ise.exe") AND `process_copy` AND Processes.process IN("*\\Windows\\System32\*", + "*\\Windows\\SysWow64\\*") AND Processes.process = "*copy*" by Processes.dest Processes.user + Processes.parent_process_name Processes.process_name Processes.process Processes.process_id + Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)`| `suspicious_copy_on_system32_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: every user may do this event but very un-ussual. +references: +- https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 +tags: + analytic_story: + - Unusual Processes + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1036.003 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 70 + confidence: 90 + risk_score: 63 + context: + - Stage:Execution + - Stage:Defense Evasion + message: execution of copy exe to copy file from $process$ in $dest$ + observable: + - name: dest + type: Endpoint + role: + - Victim + - name: User + type: User + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 61f5a11927..4c32b8f3d4 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -1,18 +1,18 @@ name: Suspicious wevtutil Usage id: 2827c0fd-e1be-4868-ae25-59d28e0f9d4f -version: 3 -date: '2020-07-22' -author: David Dorsey, Splunk +version: 4 +date: '2021-10-11' +author: David Dorsey, Michael Haag, Splunk type: TTP datamodel: - Endpoint description: The wevtutil.exe application is the windows event log utility. This searches - for wevtutil.exe with parameters for clearing the application, security, setup, + for wevtutil.exe with parameters for clearing the application, security, setup, trace or system event logs. search: '| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes - where Processes.process_name = wevtutil.exe Processes.process="*cl*" (Processes.process="*System*" - OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*") + where Processes.process_name=wevtutil.exe Processes.process IN ("* cl *", "*clear-log*") (Processes.process="*System*" + OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*" OR Processes.process="*trace*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `suspicious_wevtutil_usage_filter`' @@ -23,13 +23,13 @@ how_to_implement: You must be ingesting data that records process activity from model. known_false_positives: The wevtutil.exe application is a legitimate Windows event log utility. Administrators may use it to manage Windows event logs. -references: [] +references: + - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1070.001/T1070.001.md tags: analytic_story: - Windows Log Manipulation - Ransomware - Clop Ransomware - asset_type: '' automated_detection_testing: passed cis20: - CIS 3 diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml new file mode 100644 index 0000000000..fcf99f419e --- /dev/null +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -0,0 +1,68 @@ +name: Time Provider Persistence Registry +id: 5ba382c4-2105-11ec-8d8f-acde48001122 +version: 1 +date: '2021-09-29' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspiciouos modification of time provider + registry for persistence and autostart. This technique can allow the attacker to + persist on the compromised host and autostart as soon as the machine boot up. This + TTP can be a good indicator of suspicious behavior since this registry is not commonly + modified by normal user or even an admin. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path + ="*\\CurrentControlSet\\Services\\W32Time\\TimeProviders*" by Registry.dest Registry.user + Registry.registry_path Registry.registry_key_name Registry.registry_value_name | + `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` + | `time_provider_persistence_registry_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: unknown +references: +- https://pentestlab.blog/2019/10/22/persistence-time-providers/ +- https://attack.mitre.org/techniques/T1547/003/ +tags: + analytic_story: + - Windows Persistence Techniques + - Windows Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1547.003 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/vbscript_execution_using_wscript_app.yml b/detections/endpoint/vbscript_execution_using_wscript_app.yml new file mode 100644 index 0000000000..5cb1e55d97 --- /dev/null +++ b/detections/endpoint/vbscript_execution_using_wscript_app.yml @@ -0,0 +1,69 @@ +name: Vbscript Execution Using Wscript App +id: 35159940-228f-11ec-8a49-acde48001122 +version: 1 +date: '2021-10-01' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious wscript commandline to execute + vbscript. This technique was seen in several malware to execute malicious vbs file + using wscript application. commonly vbs script is associated to cscript process + and this can be a technique to evade process parent child detections or even some + av script emulation system. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name + = "wscript.exe" AND Processes.parent_process = "*//e:vbscript*") OR (Processes.process_name + = "wscript.exe" AND Processes.process = "*//e:vbscript*") by Processes.parent_process_name + Processes.parent_process Processes.process_name Processes.process_id Processes.process + Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `vbscript_execution_using_wscript_app_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: unknown +references: +- https://www.joesandbox.com/analysis/369332/0/html +tags: + analytic_story: + - FIN7 + - Remcos + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1059.005 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 70 + confidence: 70 + risk_score: 49 + context: + - Source:Endpoint + - Stage:Execution + message: Process name $process_name$ with commandline $process$ to execute vbsscript + observable: + - name: dest + type: Endpoint + role: + - Victim + - name: user + type: User + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/verclsid_clsid_execution.yml b/detections/endpoint/verclsid_clsid_execution.yml new file mode 100644 index 0000000000..556ef2e416 --- /dev/null +++ b/detections/endpoint/verclsid_clsid_execution.yml @@ -0,0 +1,72 @@ +name: Verclsid CLSID Execution +id: 61e9a56a-20fa-11ec-8ba3-acde48001122 +version: 1 +date: '2021-09-29' +author: Teoderick Contreras, Splunk +type: Hunting +datamodel: +- Endpoint +description: This analytic is to detect a possible abuse of verclsid to execute malicious + file through generate CLSID. This process is a normal application of windows to + verify the CLSID COM object before it is instantiated by Windows Explorer. This + hunting query can be a good pivot point to analyze what is he CLSID or COM object + pointing too to check if it is a valid application or not. +search: '| tstats `security_content_summariesonly` values(Processes.process) as process + values(Processes.parent_process) as parent_process values(Processes.process_id) + as process_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes + where `process_verclsid` AND Processes.process="*/S*" Processes.process="*/C*" AND Processes.process="*{*" + AND Processes.process="*}*" by Processes.process_name Processes.original_file_name + Processes.dest Processes.user Processes.parent_process_name Processes.parent_process + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `verclsid_clsid_execution_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product. +known_false_positives: windows can used this application for its normal COM object + validation. +references: +- https://gist.github.com/NickTyrer/0598b60112eaafe6d07789f7964290d5 +- https://bohops.com/2018/08/18/abusing-the-com-registry-structure-part-2-loading-techniques-for-evasion-and-persistence/ +tags: + analytic_story: + - Unusual Processes + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1218.012 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 50 + confidence: 50 + risk_score: 25 + context: + - source:endpoint + - stage:Defense Evasion + message: process $process_name$ to execute possible clsid commandline $process$ + in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + automated_detection_testing: passed diff --git a/detections/endpoint/winhlp32_spawning_a_process.yml b/detections/endpoint/winhlp32_spawning_a_process.yml new file mode 100644 index 0000000000..b549589720 --- /dev/null +++ b/detections/endpoint/winhlp32_spawning_a_process.yml @@ -0,0 +1,88 @@ +name: Winhlp32 Spawning a Process +id: d17dae9e-2618-11ec-b9f5-acde48001122 +version: 1 +date: '2021-10-05' +author: Michael Haag, Splunk +type: TTP +datamodel: +- Endpoint +description: The following analytic identifies winhlp32.exe, found natively in `c:\windows\`, + spawning a child process that loads a file out of appdata, programdata, or temp. + Winhlp32.exe has a rocky past in that multiple vulnerabilities were found and added + to MetaSploit. WinHlp32.exe is required to display 32-bit Help files that have the + ".hlp" file name extension. This particular instance is related to a Remcos sample + where dynwrapx.dll is added to the registry under inprocserver32, and later module + loaded by winhlp32.exe to spawn wscript.exe and load a vbs or file from disk. During + triage, review parallel processes to identify further suspicious behavior. Review + module loads for unsuspecting unsigned modules. Capture any file modifications and + analyze. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=winhlp32.exe + Processes.process IN ("*\\appdata\\*","*\\programdata\\*", "*\\temp\\*") by Processes.dest + Processes.user Processes.parent_process_name Processes.process_name Processes.original_file_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `winhlp32_spawning_a_process_filter`' +how_to_implement: To successfully implement this search you need to be ingesting information + on process that include the name of the process responsible for the changes from + your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, + confirm the latest CIM App 4.20 or higher is installed and the latest TA for the + endpoint product. +known_false_positives: False positives should be limited as winhlp32.exe is typically + not used with the latest flavors of Windows OS. However, filter as needed. +references: +- https://www.exploit-db.com/exploits/16541 +- https://tria.ge/210929-ap75vsddan +- https://www.virustotal.com/gui/file/cb77b93150cb0f7fe65ce8a7e2a5781e727419451355a7736db84109fa215a89 +tags: + analytic_story: + - Remcos + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1055 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name + - Processes.parent_process + - Processes.original_file_name + - Processes.process_name + - Processes.process + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 80 + confidence: 100 + risk_score: 80 + context: + - Source:Endpoint + - Stage:Defense Evasion + message: An instance of $parent_process_name$ spawning $process_name$ was identified + on endpoint $dest$, and is not typical activity for this process. + observable: + - name: user + type: User + role: + - Victim + - name: dest + type: Hostname + role: + - Victim + - name: parent_process_name + type: Parent Process + role: + - Parent Process + - name: process_name + type: Process + role: + - Child Process + automated_detection_testing: passed diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml new file mode 100644 index 0000000000..1d680f7db2 --- /dev/null +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -0,0 +1,78 @@ +name: Wscript Or Cscript Suspicious Child Process +id: 1f35e1da-267b-11ec-90a9-acde48001122 +version: 1 +date: '2021-10-06' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious spawned process by wscript or + cscript process. This technique was a common technique used by adversaries and malware + to execute different LOLBIN, other script like powershell or create a suspended + process to inject its code as a defense evasion. This TTP may detect some normal + script that using several application tool that are in the list of the child process + it detects but a good pivot and indicator that a script is may execute suspicious + code. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name + IN ("cscript.exe", "wscript.exe") Processes.process_name IN ("regsvr32.exe", "rundll32.exe","winhlp32.exe","certutil.exe","msbuild.exe","cmd.exe","powershell*","wmic.exe","mshta.exe") + by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process + Processes.process_name Processes.process Processes.process_id Processes.parent_process_id + | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` + | `wscript_or_cscript_suspicious_child_process_filter`' +how_to_implement: To successfully implement this search, you need to be ingesting + logs with the process name, parent process, and command-line executions from your + endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the + Sysmon TA. +known_false_positives: user may create vbs or js script that use several tool as part + of its execution. +references: +- https://www.hybrid-analysis.com/sample/8da5b75b6380a41eee3a399c43dfe0d99eeefaa1fd21027a07b1ecaa4cd96fdd?environmentId=120 +tags: + analytic_story: + - FIN7 + - Remcos + - Unusual Processes + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1055 + - T1543 + - T1134.004 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Processes.dest + - Processes.user + - Processes.parent_process_name #parent process name + - Processes.parent_process #parent cmdline + - Processes.original_file_name + - Processes.process_name #process name + - Processes.process #process cmdline + - Processes.process_id + - Processes.parent_process_path + - Processes.process_path + - Processes.parent_process_id + security_domain: endpoint + impact: 70 + confidence: 70 + risk_score: 49 + context: + - Source:Endpoint + - Stage:Execution + message: wscript or cscript parent process spawned $process_name$ in $dest$ + observable: + - name: dest + type: Endpoint + role: + - Victim + - name: user + type: User + role: + - Victim + automated_detection_testing: passed diff --git a/detections/experimental/endpoint/print_processor_registry_autostart.yml b/detections/experimental/endpoint/print_processor_registry_autostart.yml new file mode 100644 index 0000000000..dab28eac10 --- /dev/null +++ b/detections/experimental/endpoint/print_processor_registry_autostart.yml @@ -0,0 +1,69 @@ +name: Print Processor Registry Autostart +id: 1f5b68aa-2037-11ec-898e-acde48001122 +version: 1 +date: '2021-09-28' +author: Teoderick Contreras, Splunk +type: TTP +datamodel: +- Endpoint +description: This analytic is to detect a suspicious modification or new registry entry regarding print processor. + This registry is known to be abuse by turla or other APT to gain persistence and privilege escalation to the compromised machine. + This is done by adding the malicious dll payload on the new created key in this registry that will be executed as it restarted the spoolsv.exe process and services. +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime + max(_time) as lastTime FROM datamodel=Endpoint.Registry + where Registry.registry_path ="*\\Control\\Print\\Environments\\Windows x64\\Print Processors*" + by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name Registry.registry_value_name + | `security_content_ctime(lastTime)` + | `security_content_ctime(firstTime)` + | `drop_dm_object_name(Registry)` + | `print_processor_registry_autostart_filter`' +how_to_implement: To successfully implement this search, you must be ingesting data + that records registry activity from your hosts to populate the endpoint data model + in the registry node. This is typically populated via endpoint detection-and-response + product, such as Carbon Black or endpoint data sources, such as Sysmon. The data + used for this search is typically generated via logs that report reads and writes + to the registry. +known_false_positives: possible new printer installation may add driver component on this registry. +references: +- https://attack.mitre.org/techniques/T1547/012/ +- https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/ +tags: + analytic_story: + - Windows Persistence Techniques + - Windows Privilege Escalation + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log + kill_chain_phases: + - Exploitation + mitre_attack_id: + - T1547.012 + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + required_fields: + - _time + - Registry.dest + - Registry.user + - Registry.registry_path + - Registry.registry_key_name + - Registry.registry_value_name + security_domain: endpoint + impact: 80 + confidence: 100 + # (impact * confidence)/100 + risk_score: 80 + context: + - source:endpoint + - stage:Privilege Escalation Persistence + message: modified/added/deleted registry entry $Registry.registry_path$ in $dest$ + observable: + - name: dest + type: Hostname + role: + - Victim + - name: user + type: user + role: + - Victim + \ No newline at end of file diff --git a/macros/process_copy.yml b/macros/process_copy.yml new file mode 100644 index 0000000000..06d1c3b28f --- /dev/null +++ b/macros/process_copy.yml @@ -0,0 +1,3 @@ +definition: (Processes.process_name=copy.exe OR Processes.original_file_name=copy.exe OR Processes.process_name=xcopy.exe OR Processes.original_file_name=xcopy.exe) +description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/ +name: process_copy \ No newline at end of file diff --git a/macros/process_sdelete.yml b/macros/process_sdelete.yml new file mode 100644 index 0000000000..2a5bc306d6 --- /dev/null +++ b/macros/process_sdelete.yml @@ -0,0 +1,3 @@ +definition: (Processes.process_name=sdelete.exe OR Processes.original_file_name=sdelete.exe) +description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/ +name: process_sdelete \ No newline at end of file diff --git a/macros/process_verclsid.yml b/macros/process_verclsid.yml new file mode 100644 index 0000000000..a70fbd2e0d --- /dev/null +++ b/macros/process_verclsid.yml @@ -0,0 +1,3 @@ +definition: (Processes.process_name=verclsid.exe OR Processes.original_file_name=verclsid.exe) +description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/ +name: process_verclsid \ No newline at end of file diff --git a/stories/dev_sec_ops.yml b/stories/dev_sec_ops.yml index e800aef9d9..b7008f38b2 100644 --- a/stories/dev_sec_ops.yml +++ b/stories/dev_sec_ops.yml @@ -14,7 +14,7 @@ narrative: DevSecOps is a collaborative framework, which thinks about applicatio references: - https://www.redhat.com/en/topics/devops/what-is-devsecops tags: - analytic_story: DevSecOps + analytic_story: Dev Sec Ops category: - Cloud Security product: diff --git a/tests/endpoint/active_setup_registry_autostart.test.yml b/tests/endpoint/active_setup_registry_autostart.test.yml new file mode 100644 index 0000000000..e1fb06c684 --- /dev/null +++ b/tests/endpoint/active_setup_registry_autostart.test.yml @@ -0,0 +1,12 @@ +name: Active Setup Registry Autostart Unit Test +tests: +- name: Active Setup Registry Autostart + file: endpoint/active_setup_registry_autostart.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/t1547.014/active_setup_stubpath/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/change_default_file_association.test.yml b/tests/endpoint/change_default_file_association.test.yml new file mode 100644 index 0000000000..42dd4b8324 --- /dev/null +++ b/tests/endpoint/change_default_file_association.test.yml @@ -0,0 +1,12 @@ +name: Change Default File Association Unit Test +tests: +- name: Change Default File Association + file: endpoint/change_default_file_association.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.001/txtfile_reg/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/disable_security_logs_using_minint_registry.test.yml b/tests/endpoint/disable_security_logs_using_minint_registry.test.yml new file mode 100644 index 0000000000..b54ddced69 --- /dev/null +++ b/tests/endpoint/disable_security_logs_using_minint_registry.test.yml @@ -0,0 +1,12 @@ +name: Disable Security Logs Using MiniNt Registry Unit Test +tests: +- name: Disable Security Logs Using MiniNt Registry + file: endpoint/disable_security_logs_using_minint_registry.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/minint_reg/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/disable_uac_remote_restriction.test.yml b/tests/endpoint/disable_uac_remote_restriction.test.yml new file mode 100644 index 0000000000..4adb6f2d25 --- /dev/null +++ b/tests/endpoint/disable_uac_remote_restriction.test.yml @@ -0,0 +1,12 @@ +name: Disable UAC Remote Restriction Unit Test +tests: +- name: Disable UAC Remote Restriction + file: endpoint/disable_uac_remote_restriction.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/LocalAccountTokenFilterPolicy/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/enable_wdigest_uselogoncredential_registry.test.yml b/tests/endpoint/enable_wdigest_uselogoncredential_registry.test.yml new file mode 100644 index 0000000000..735c79499f --- /dev/null +++ b/tests/endpoint/enable_wdigest_uselogoncredential_registry.test.yml @@ -0,0 +1,12 @@ +name: Enable WDigest UseLogonCredential Registry Unit Test +tests: +- name: Enable WDigest UseLogonCredential Registry + file: endpoint/enable_wdigest_uselogoncredential_registry.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/wdigest_enable/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/etw_registry_disabled.test.yml b/tests/endpoint/etw_registry_disabled.test.yml new file mode 100644 index 0000000000..4decd04292 --- /dev/null +++ b/tests/endpoint/etw_registry_disabled.test.yml @@ -0,0 +1,12 @@ +name: ETW Registry Disabled Unit Test +tests: +- name: ETW Registry Disabled + file: endpoint/etw_registry_disabled.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/etw_disable/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/logon_script_event_trigger_execution.test.yml b/tests/endpoint/logon_script_event_trigger_execution.test.yml new file mode 100644 index 0000000000..dcb74a0a02 --- /dev/null +++ b/tests/endpoint/logon_script_event_trigger_execution.test.yml @@ -0,0 +1,12 @@ +name: Logon Script Event Trigger Execution Unit Test +tests: +- name: Logon Script Event Trigger Execution + file: endpoint/logon_script_event_trigger_execution.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1037.001/logonscript_reg/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/malicious_inprocserver32_modification.test.yml b/tests/endpoint/malicious_inprocserver32_modification.test.yml new file mode 100644 index 0000000000..dd97ac887f --- /dev/null +++ b/tests/endpoint/malicious_inprocserver32_modification.test.yml @@ -0,0 +1,12 @@ +name: Malicious InProcServer32 Modification Unit Test +tests: +- name: Malicious InProcServer32 Modification + file: endpoint/malicious_inprocserver32_modification.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/msbuild_suspicious_spawned_by_script_process.test.yml b/tests/endpoint/msbuild_suspicious_spawned_by_script_process.test.yml new file mode 100644 index 0000000000..4407f84aa1 --- /dev/null +++ b/tests/endpoint/msbuild_suspicious_spawned_by_script_process.test.yml @@ -0,0 +1,12 @@ +name: MSBuild Suspicious Spawned By Script Process Unit Test +tests: +- name: MSBuild Suspicious Spawned By Script Process + file: endpoint/msbuild_suspicious_spawned_by_script_process.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/regsvr32_silent/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/print_processor_registry_autostart.test.yml b/tests/endpoint/print_processor_registry_autostart.test.yml new file mode 100644 index 0000000000..0a7ef8f35f --- /dev/null +++ b/tests/endpoint/print_processor_registry_autostart.test.yml @@ -0,0 +1,12 @@ +name: Print Processor Registry Autostart Unit Test +tests: +- name: Print Processor Registry Autostart + file: experimental/endpoint/print_processor_registry_autostart.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-365d' + latest_time: 'now' + attack_data: + - file_name: sysmon_print.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.012/print_reg/sysmon_print.log + source: WinEventLog:Microsoft-Windows-PrintService/Operational + sourcetype: WinEventLog \ No newline at end of file diff --git a/tests/endpoint/process_writing_dynamicwrapperx.test.yml b/tests/endpoint/process_writing_dynamicwrapperx.test.yml new file mode 100644 index 0000000000..9b6cdead63 --- /dev/null +++ b/tests/endpoint/process_writing_dynamicwrapperx.test.yml @@ -0,0 +1,12 @@ +name: Process Writing DynamicWrapperX Unit Test +tests: +- name: Process Writing DynamicWrapperX + file: endpoint/process_writing_dynamicwrapperx.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/regsvr32_silent_param_dll_loading.test.yml b/tests/endpoint/regsvr32_silent_param_dll_loading.test.yml new file mode 100644 index 0000000000..a28aa579c6 --- /dev/null +++ b/tests/endpoint/regsvr32_silent_param_dll_loading.test.yml @@ -0,0 +1,12 @@ +name: Regsvr32 Silent Param Dll Loading Unit Test +tests: +- name: Regsvr32 Silent Param Dll Loading + file: endpoint/regsvr32_silent_param_dll_loading.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/rundll32_shimcache_flush.test.yml b/tests/endpoint/rundll32_shimcache_flush.test.yml new file mode 100644 index 0000000000..2a416381a6 --- /dev/null +++ b/tests/endpoint/rundll32_shimcache_flush.test.yml @@ -0,0 +1,12 @@ +name: Rundll32 Shimcache Flush Unit Test +tests: +- name: Rundll32 Shimcache Flush + file: endpoint/rundll32_shimcache_flush.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1112/shimcache_flush/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/screensaver_event_trigger_execution.test.yml b/tests/endpoint/screensaver_event_trigger_execution.test.yml new file mode 100644 index 0000000000..1f3ad83e56 --- /dev/null +++ b/tests/endpoint/screensaver_event_trigger_execution.test.yml @@ -0,0 +1,12 @@ +name: Screensaver Event Trigger Execution Unit Test +tests: +- name: Manual datasets generation for Screensaver Event Trigger Execution. + file: endpoint/screensaver_event_trigger_execution.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1546.002/scrnsave_reg/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/sdelete_application_execution.test.yml b/tests/endpoint/sdelete_application_execution.test.yml new file mode 100644 index 0000000000..e86bfc34a9 --- /dev/null +++ b/tests/endpoint/sdelete_application_execution.test.yml @@ -0,0 +1,12 @@ +name: Sdelete Application Execution Unit Test +tests: +- name: Sdelete Application Execution + file: endpoint/sdelete_application_execution.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1485/sdelete/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/suspicious_copy_on_system32.test.yml b/tests/endpoint/suspicious_copy_on_system32.test.yml new file mode 100644 index 0000000000..918c57dd1b --- /dev/null +++ b/tests/endpoint/suspicious_copy_on_system32.test.yml @@ -0,0 +1,12 @@ +name: Suspicious Copy on System32 Unit Test +tests: +- name: Suspicious Copy on System32 + file: endpoint/suspicious_copy_on_system32.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/copy_sysmon/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/time_provider_persistence_registry.test.yml b/tests/endpoint/time_provider_persistence_registry.test.yml new file mode 100644 index 0000000000..4de49c3411 --- /dev/null +++ b/tests/endpoint/time_provider_persistence_registry.test.yml @@ -0,0 +1,12 @@ +name: Time Provider Persistence Registry Unit Test +tests: +- name: Time Provider Persistence Registry + file: endpoint/time_provider_persistence_registry.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1547.003/timeprovider_reg/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/vbscript_execution_using_wscript_app.test.yml b/tests/endpoint/vbscript_execution_using_wscript_app.test.yml new file mode 100644 index 0000000000..2139a83584 --- /dev/null +++ b/tests/endpoint/vbscript_execution_using_wscript_app.test.yml @@ -0,0 +1,12 @@ +name: Vbscript Execution Using Wscript App Unit Test +tests: +- name: Vbscript Execution Using Wscript App + file: endpoint/vbscript_execution_using_wscript_app.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/verclsid_clsid_execution.test.yml b/tests/endpoint/verclsid_clsid_execution.test.yml new file mode 100644 index 0000000000..cbbc1bfc62 --- /dev/null +++ b/tests/endpoint/verclsid_clsid_execution.test.yml @@ -0,0 +1,12 @@ +name: Verclsid CLSID Execution Unit Test +tests: +- name: Verclsid CLSID Execution + file: endpoint/verclsid_clsid_execution.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.012/verclsid_exec/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/winhlp32_spawning_a_process.test.yml b/tests/endpoint/winhlp32_spawning_a_process.test.yml new file mode 100644 index 0000000000..ff803d49aa --- /dev/null +++ b/tests/endpoint/winhlp32_spawning_a_process.test.yml @@ -0,0 +1,12 @@ +name: Winhlp32 Spawning a Process Unit Test +tests: +- name: Winhlp32 Spawning a Process + file: endpoint/winhlp32_spawning_a_process.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: windows-sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/remcos/remcos/windows-sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file diff --git a/tests/endpoint/wscript_or_cscript_suspicious_child_process.test.yml b/tests/endpoint/wscript_or_cscript_suspicious_child_process.test.yml new file mode 100644 index 0000000000..9b99129f6d --- /dev/null +++ b/tests/endpoint/wscript_or_cscript_suspicious_child_process.test.yml @@ -0,0 +1,12 @@ +name: Wscript Or Cscript Suspicious Child Process Unit Test +tests: +- name: Wscript Or Cscript Suspicious Child Process + file: endpoint/wscript_or_cscript_suspicious_child_process.yml + pass_condition: '| stats count | where count > 0' + earliest_time: '-24h' + latest_time: 'now' + attack_data: + - file_name: sysmon.log + data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.005/vbs_wscript/sysmon.log + source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational + sourcetype: xmlwineventlog \ No newline at end of file